VYPR

Password Recovery

by Password Recovery Project

CVEs (5)

  • CVE-2020-37215HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the…

  • CVE-2020-37193HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by providing maliciously crafted input. Attackers can create a specially prepared text file with specific characters to trigger an application crash when…

  • CVE-2023-3222HigSep 4, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all…

  • CVE-2019-25477MedMar 11, 2026
    risk 0.40cvss 6.2epss 0.00

    RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can craft a malicious input string exceeding 6000 bytes and paste it into the User…

  • CVE-2023-3221MedSep 4, 2023
    risk 0.34cvss 5.3epss 0.00

    User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.