Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerabl
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows
VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit thi
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability e
Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticatio
Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset
The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the acc
LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HT
KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-e
A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software ve
ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php cause
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Pa
Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templat
Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the cont
IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to ob
Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reus
A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerabili
A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the functi
A vulnerability, which was classified as critical, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This affects the
A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function fo
A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sy
A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown fun
A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Aff
A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects
A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown fu
The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and includi
A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the
A vulnerability was found in PHPGurukul Online Library Management System 3.0. It has been declared as problematic. Affec
A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vu
This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API e
Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.
An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mech
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticat
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin pa
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up t
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affect
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVi
Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgot
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper sec
TP-Link Tapo C210 Password Recovery Authentication Bypass Vulnerability. This vulnerability allows network-adjacent atta
A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user inte
HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links
The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in al
The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and in
Frequently Asked Questions
What is CWE-640?
CWE-640 (CWE-640) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-640?
There are 354 CVE records associated with CWE-640 in our database. Of these, 100 are critical severity, 119 are high severity, and 74 are medium severity.
How can I protect against CWE-640 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-640 using AI-powered security agents.
Detect CWE-640 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-640 vulnerabilities across your infrastructure.
Get Started