Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-620
Weakness type CWE-620 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 25 | 24 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▃▁▄▄▄▆█▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 3 · 2026-06 3 · 2026-07 3 · 2026-08 5 · 2026-09 7 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-15964 | 9.8 | 58.1 | — | Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified P… |
| CVE-2026-91995 | 9.3 | 57.6 | — | pig before 4.1.0 Unverified Password Change via /register/password |
| CVE-2026-46623 | 7.4 | 50.2 | — | OpenAM Account Takeover via Unverified Password Change in OAuth2 Module |
| CVE-2026-54176 | 6.5 | 49.4 | — | backpack/crud: MyAccountController allows changing the login email without a current-pa… |
| CVE-2026-12692 | 9.8 | 49.0 | — | Improper Authentication in Vimesoft's Enterprise Video Platform |
| CVE-2026-54801 | 8.6 | 47.8 | — | — |
| CVE-2026-86260 | 5.5 | 46.6 | — | sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverifi… |
| CVE-2026-5386 | 9.1 | 46.3 | — | KMW CCTV Security Cameras Unverified Password Change |
| CVE-2025-5482 | 8.8 | 45.0 | — | Sunshine Photo Cart <= 3.4.11 - Authenticated (Subscriber+) Privilege Escalation |
| CVE-2026-54175 | 7.6 | 44.2 | — | backpack/crud: Unverified password change in MyAccountController via mass assignment |
| CVE-2026-85591 | 7.1 | 42.0 | — | phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change |
| CVE-2026-56305 | 8.7 | 42.0 | — | Capgo - Authentication Bypass in Password Change via Missing Current Password Validation |
| CVE-2025-71328 | 8.7 | 38.7 | — | Flowise - Unverified Password Change via Account Settings |
| CVE-2025-70082 | 5.1 | 37.6 | — | Lantronix EDS3000PS Unverified Password Change |
| CVE-2026-92467 | 8.7 | 37.4 | — | microservices-platform through 6.0.0 Unverified Password Change via /users/password |
| CVE-2026-76633 | 8.6 | 35.9 | — | WeGIA < 3.9.2 Authorization Bypass Password Change via alterarSenha |
| CVE-2026-77644 | 9.3 | 35.0 | — | Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliabilit… |
| CVE-2025-71337 | 8.7 | 34.3 | — | Flowise - Unverified Email Change via Account Profile Endpoint |
| CVE-2025-67041 | 8.6 | 33.7 | — | Lantronix EDS3000PS OS Command Injection |
| CVE-2026-17599 | 6.9 | 24.7 | — | Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| flowise | 2 |
| lantronix | 2 |
| laravel-backpack | 2 |
| britcoder | 1 |
| capgo | 1 |
| concrete cms | 1 |
| devolutions | 1 |
| kmw | 1 |
| labredescefetrj | 1 |
| laurent22 | 1 |
| openidentityplatform | 1 |
| opf | 1 |
| pig-mesh | 1 |
| ptc | 1 |
| semaphoreui | 1 |