CWE-620: CWE-620

44
Total CVEs
16
Critical
15
High
7.9
Avg CVSS

Yearly Trend

2026
5
2025
27
2024
7
2023
2
2022
2

Top Affected Vendors

1 Johnsoncontrols 2
2 Ibm 2
3 Level1 1
4 Ba Booking 1
5 Utt 1
6 Eskooly 1
7 Dlink 1
8 Opencrx 1
9 Corebos 1
10 Progress 1

All CWE-620 CVEs (44)

CVE-2024-20419
10.0

This critical vulnerability in Cisco Smart Software Manager On-Prem allows unauthenticated remote attackers to change any user's password, including a...

Jul 17, 2024
CVE-2025-1107
9.9

CVE-2025-1107 is an unverified password change vulnerability in Janto software that allows unauthenticated attackers to change any user's password wit...

Feb 7, 2025
CVE-2024-33699
9.9

The LevelOne WBR-6012 router's web interface contains an authentication bypass vulnerability that allows attackers to change the administrator passwor...

Oct 30, 2024
CVE-2025-63362
9.8

This vulnerability allows attackers to set blank administrator credentials on Waveshare serial-to-Ethernet/Wi-Fi gateways, enabling complete authentic...

Dec 4, 2025
CVE-2025-9286
9.8

This vulnerability allows unauthenticated attackers to reset passwords of any WordPress user, including administrators, through the Appy Pie Connect f...

Oct 3, 2025
CVE-2025-10159
9.8

An authentication bypass vulnerability in Sophos AP6 Series Wireless Access Points allows remote attackers to gain administrative privileges without v...

Sep 9, 2025
CVE-2025-4606
9.8

The Sala WordPress theme has an authentication bypass vulnerability that allows unauthenticated attackers to change any user's password, including adm...

Jul 9, 2025
CVE-2024-12827
9.8

This vulnerability allows unauthenticated attackers to reset passwords for any user account in the DWT - Directory & Listing WordPress Theme, includin...

Jun 27, 2025
CVE-2025-4322
EPSS 32.3% 9.8

The Motors WordPress theme has a critical privilege escalation vulnerability that allows unauthenticated attackers to change any user's password, incl...

May 20, 2025
CVE-2025-3603
9.8

The Flynax Bridge WordPress plugin has a critical authentication bypass vulnerability that allows unauthenticated attackers to reset any user's passwo...

Apr 24, 2025
CVE-2024-12860
9.8

This vulnerability allows unauthenticated attackers to reset passwords for any user account in CarSpot WordPress theme, including administrators. Atta...

Feb 18, 2025
CVE-2024-13375
EPSS 12% 9.8

The Adifier System WordPress plugin has a critical privilege escalation vulnerability that allows unauthenticated attackers to reset any user's passwo...

Jan 18, 2025
CVE-2024-26520
9.8

This critical vulnerability in Hangzhou Xiongwei Technology's Restaurant Digital Comprehensive Management platform allows attackers to bypass authenti...

Jul 26, 2024
CVE-2024-37998
9.8

This vulnerability allows unauthorized attackers to reset administrative passwords without knowing the current password when auto-login is enabled, gr...

Jul 22, 2024
CVE-2023-3069
9.8

CVE-2023-3069 is an unverified password change vulnerability in coreBOS CRM that allows attackers to change any user's password without authentication...

Jun 2, 2023
CVE-2020-7378
9.1

CVE-2020-7378 allows unauthenticated attackers to change any user's password in OpenCRX, including administrative accounts, by connecting to the vulne...

Nov 24, 2020
CVE-2026-24443
8.8

EventSentry Web Reports interface versions before 6.0.1.20 contain an unverified password change vulnerability. Attackers with temporary access to an ...

Feb 24, 2026
CVE-2026-24440
8.8

This vulnerability allows unauthorized password changes on Tenda W30E V2 routers without verifying the current password. Attackers who gain access to ...

Jan 26, 2026
CVE-2025-3607
8.8

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to change any user's password, including administrators...

Apr 24, 2025
CVE-2024-9431
8.8

This vulnerability in transformeroptimus/superagi v0.0.14 allows authenticated users to change other users' passwords after logging in, enabling accou...

Mar 20, 2025
CVE-2024-28143
8.4

This vulnerability allows attackers to change any user's password without knowing the current password via the /cgi/admin.cgi endpoint. Attackers can ...

Dec 12, 2024
CVE-2025-62425
8.3

A logic flaw in Matrix Authentication Service (MAS) versions 0.20.0 through 1.4.0 allows authenticated attackers to perform sensitive account operatio...

Oct 16, 2025
CVE-2025-61536
8.2

This vulnerability in FelixRiddle's dev-jobs-handlebars 1.0 allows attackers to hijack password reset links by manipulating the Host header. Attackers...

Oct 16, 2025
CVE-2025-22381
8.2

Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality that allows attackers to reset user passwords by manipulati...

Oct 16, 2025
CVE-2024-27715
8.2

CVE-2024-27715 is an authentication bypass vulnerability in Eskooly Free Online School Management Software that allows remote attackers to change pass...

Jul 5, 2024
CVE-2025-13148
8.1

This vulnerability in IBM Aspera Orchestrator allows authenticated users to change other users' passwords without knowing their current passwords. Thi...

Dec 11, 2025
CVE-2024-13373
8.1

The Exertio Framework WordPress plugin has a critical authentication bypass vulnerability that allows unauthenticated attackers to reset any user's pa...

Mar 1, 2025
CVE-2022-21934
8.0

This vulnerability in Metasys building automation servers allows authenticated users to lock out other users or take over their accounts. It affects M...

May 6, 2022
CVE-2022-21935
7.5

This vulnerability in Johnson Controls Metasys building automation systems allows attackers to change passwords without verification. It affects Metas...

Jun 15, 2022
CVE-2023-5844
7.2

This vulnerability allows unauthenticated attackers to change passwords for any user account in Pimcore's admin-ui-classic-bundle without verification...

Oct 30, 2023
CVE-2025-61132
7.1

A Host Header Injection vulnerability in levlaz braindump v0.4.14 allows attackers to manipulate password reset links by injecting malicious Host head...

Oct 23, 2025
CVE-2025-46389
6.5

CVE-2025-46389 is an authentication bypass vulnerability (CWE-620) that allows attackers to change passwords without proper verification. This affects...

Aug 6, 2025
CVE-2024-41796
6.5

This vulnerability allows unauthenticated attackers to change the login password on SENTRON 7KT PAC1260 Data Manager devices without knowing the curre...

Apr 8, 2025
CVE-2024-45647
5.6

This vulnerability in IBM Security Verify Access allows unauthenticated attackers to reset passwords for expired user accounts without knowing the cur...

Jan 20, 2025
CVE-2025-4552
5.4

This vulnerability in ContiNew Admin allows unauthenticated attackers to remotely reset the super administrator password without verification. Affects...

May 12, 2025
CVE-2025-6097
5.3

This vulnerability allows remote attackers to change the administrator password without verification on UTT 进取 750W devices up to version 5.0. Att...

Jun 16, 2025
CVE-2025-4903
5.3

This critical vulnerability in D-Link DI-7003GV2 routers allows remote attackers to change passwords without verification via a specific web interface...

May 19, 2025
CVE-2024-8794
5.3

The BA Book Everything WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to reset any user's password ...

Sep 24, 2024
CVE-2025-3849
4.3

This vulnerability allows remote attackers to change student passwords without proper verification in the SpringBoot-Vue-OnlineExam system. By manipul...

Apr 22, 2025
CVE-2025-3793
4.2

The Buddypress Force Password Change WordPress plugin contains an authentication bypass vulnerability that allows authenticated attackers (subscriber-...

Apr 24, 2025
CVE-2025-11235
3.7

This vulnerability allows attackers to change passwords without proper verification in Progress MOVEit Transfer's REST API modules on Windows. It affe...

Jan 7, 2026
CVE-2026-2543
2.7

This vulnerability in vichan-devel vichan allows attackers to remotely change passwords without proper verification. It affects users of vichan up to ...

Feb 16, 2026
CVE-2025-14751
N/A

This authentication bypass vulnerability allows low-privileged users to escalate privileges without proper credential verification. It affects systems...

Jan 22, 2026
CVE-2025-67719
N/A

Ibexa DXP versions 5.0.0-beta1 through 5.0.3 have a password validation bypass vulnerability. Authenticated users can change their password without pr...

Dec 11, 2025

About CWE-620 (CWE-620)

Our database tracks 44 CVEs classified as CWE-620, with 16 rated critical and 15 rated high severity. The average CVSS score for CWE-620 vulnerabilities is 7.9.

External reference: View CWE-620 on MITRE CWE →

Monitor CWE-620 Vulnerabilities

Get alerted when new CWE-620 CVEs affect your infrastructure.

Start Monitoring Free