Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-620

Unverified Password Change

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

88
Assigned CVEs
186th
Commonality Rank
7.8
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-620 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 17, 2017
8 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

88 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-20419CRITICAL
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any use
Jul 17, 202410.091NOYES
CVE-2025-4322CRITICAL
The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly valida
May 20, 20259.854NOYES
CVE-2026-12692CRITICAL
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 befor
Jul 17, 20269.841NONO
CVE-2026-5386CRITICAL
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a k
May 29, 20269.139NONO
CVE-2024-48887CRITICAL
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
Apr 8, 20259.839NONO
CVE-2024-12824CRITICAL
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. This is due to the
Mar 1, 20259.839NOYES
CVE-2026-56305HIGH
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current passw
Jul 10, 20268.336NONO
CVE-2025-71328HIGH
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section
Jun 25, 20268.836NONO
CVE-2025-71337HIGH
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a
Jun 23, 20268.336NONO
CVE-2025-63362CRITICAL
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to set the Administrator password
Dec 4, 20259.834NONO
View all 88 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
11%
16%
6.0-6.9
13%
26%
7.0-7.9
28%
11%
8.0-8.9
32%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.1% of CVEs· 89th percentile
Nuclei
3 CVEs
3.4% of CVEs· 93rd percentile
ExploitDB
1 CVE
1.1% of CVEs· 83rd percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products