* Encrypting tokens and expecting users to feed back the same encrypted token, and failing to authenticate.
* Simple parse errors and SQL injection on the tokens themselves.
* Exploitable generation (for instance, non-cryptographic RNGs) for the tokens themselves.
* Having multi-page flows starting from the receipt and validation of a reset token, and then having standard web flaws somewhere in that flow (for instance: userid is validated only at the start of the flow).
* Mishandling of cases where users have multiple outstanding reset requests.
* Accepting the email address to send token to from web user, validating the address, and then using the user input directly as the email address to send the token to; as in: systems that will send token to user@real.com;attacker@evil.com.
One bug everyone has in their password resets: they don't cancel outstanding tokens when users change their passwords, so that long after a user has reset their password, their email boxes still contain password-equivalent tokens. That's not a high-severity bug, but it's a meaningful one.