Skip to main content

CWE archive

CWE-620 CVEs

Programmatic archive

88 CVEs tagged with CWE-62027 Critical, 30 High, 24 Medium, 7 Low, 0 Unrated.

CVE-2026-12692

Published Jul 17, 2026

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 befo…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-56305

Published Jul 10, 2026

Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current pass…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-54801

Published Jul 9, 2026

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application cont…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-44733

Published Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permit…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-71328

Published Jun 25, 2026

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71337

Published Jun 23, 2026

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2026-5386

Published May 29, 2026

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2026-9249

Published May 22, 2026

Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This iss…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8327

Published May 21, 2026

Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw PO…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42084

Published May 4, 2026

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password…

CVSS 8.1 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-40588

Published Apr 21, 2026

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit/ does not include a current_password field and does not ve…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-25653

Published Mar 30, 2026

Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-30458

Published Mar 26, 2026

An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-24443

Published Feb 24, 2026

EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality of the Web Reports interface. The password chang…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-2543

Published Feb 16, 2026

A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler.…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-24440

Published Jan 26, 2026

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verificati…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-14751

Published Jan 22, 2026

A low-privileged user can bypass account credentials without confirming the user's current authentication state, which may lead to unauthorized privilege escalation.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-11235

Published Jan 7, 2026

Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13148

Published Dec 11, 2025

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-67719

Published Dec 11, 2025

Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 an erro…

CVSS 8.5 · High

CVE-2025-59808

Published Dec 9, 2025

An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all vers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 88 CVEsPage 1 of 4