When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
Volume of CVEs assigned to CWE-620 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
88 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-20419CRITICAL A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any use | Jul 17, 2024 | 10.0 | 91 | NO | YES |
CVE-2025-4322CRITICAL The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly valida | May 20, 2025 | 9.8 | 54 | NO | YES |
CVE-2026-12692CRITICAL Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.
This issue affects Enterprise Video Platform: from 3.11.0.0 befor | Jul 17, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-5386CRITICAL The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a k | May 29, 2026 | 9.1 | 39 | NO | NO |
CVE-2024-48887CRITICAL A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request | Apr 8, 2025 | 9.8 | 39 | NO | NO |
CVE-2024-12824CRITICAL The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. This is due to the | Mar 1, 2025 | 9.8 | 39 | NO | YES |
CVE-2026-56305HIGH Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current passw | Jul 10, 2026 | 8.3 | 36 | NO | NO |
CVE-2025-71328HIGH Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section | Jun 25, 2026 | 8.8 | 36 | NO | NO |
CVE-2025-71337HIGH Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a | Jun 23, 2026 | 8.3 | 36 | NO | NO |
CVE-2025-63362CRITICAL Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to set the Administrator password | Dec 4, 2025 | 9.8 | 34 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.