Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after passwo
blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a password reset is initiated, a 128-charac
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the fi
A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file
Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification
An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the
MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each pass
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studioc
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry
Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: P
A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can
A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the
A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This a
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by
The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthe
An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information
A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown pr
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with ph
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).
A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up t
A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the fi
A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode o
A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file i
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `Client
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() functi
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be use
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their p
An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak pa
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, lea
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain
An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due t
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is
TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of s
OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attacke
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus befor
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confi
Frequently Asked Questions
What is CWE-640?
CWE-640 (CWE-640) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-640?
There are 152 CVE records associated with CWE-640 in our database. Of these, 55 are critical severity, 53 are high severity, and 29 are medium severity.
How can I protect against CWE-640 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-640 using AI-powered security agents.
Detect CWE-640 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-640 vulnerabilities across your infrastructure.
Get Started