Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-640

MITRE ↗

CWE-640

100
CRITICAL
119
HIGH
74
MEDIUM
14
LOW
313 CVEs · Page 3/7
8.8
CVE-2024-32642

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerabl

8.1
CVE-2025-1570

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to

8.1
CVE-2025-52560

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows

8.1
CVE-2025-41251

VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit thi

8.1
CVE-2025-64101

Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability e

8.1
CVE-2025-8855

Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticatio

8.1
CVE-2025-62406

Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset

7.5
CVE-2025-53704

The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the acc

7.5
CVE-2023-53958

LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HT

7.1
CVE-2025-65203

KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-e

7.0
CVE-2025-61977

A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software ve

6.8
CVE-2025-62709

ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php cause

6.5
CVE-2024-12604

Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Pa

6.4
CVE-2025-56748

Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templat

6.1
CVE-2025-55030

Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the cont

5.9
CVE-2024-43190

IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to ob

5.4
CVE-2025-1231

Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reus

5.4
CVE-2025-4552

A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerabili

5.3
CVE-2025-0331

A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the functi

5.3
CVE-2025-4903

A vulnerability, which was classified as critical, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This affects the

5.3
CVE-2025-6097

A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function fo

5.3
CVE-2025-10322

A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sy

5.3
CVE-2025-13565

A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown fun

5.3
CVE-2025-14696

A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Aff

4.3
CVE-2025-3849

A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects

4.3
CVE-2025-7948

A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown fu

4.3
CVE-2025-14783

The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and includi

3.7
CVE-2025-15398

A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the

3.1
CVE-2025-2093

A vulnerability was found in PHPGurukul Online Library Management System 3.0. It has been declared as problematic. Affec

2.7
CVE-2025-7881

A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vu

CVE-2025-29995

This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API e

CVE-2025-53373

Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled

10.0
CVE-2023-7028 KEV

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.

9.8
CVE-2024-5404

An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mech

9.8
CVE-2024-38468

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.

9.8
CVE-2024-38287

The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticat

9.8
CVE-2024-8878

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin pa

9.8
CVE-2024-48428

An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.

9.8
CVE-2024-11103

The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up t

9.8
CVE-2024-53552

CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

9.4
CVE-2024-47547

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their

9.1
CVE-2024-2862

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affect

8.8
CVE-2023-49589

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVi

8.8
CVE-2024-22454

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgot

8.8
CVE-2024-27899

Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper sec

8.8
CVE-2023-35717

TP-Link Tapo C210 Password Recovery Authentication Bypass Vulnerability. This vulnerability allows network-adjacent atta

8.8
CVE-2024-45980

A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user inte

8.3
CVE-2024-6203

HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links

8.1
CVE-2023-7264

The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in al

8.1
CVE-2024-6125

The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and in

Frequently Asked Questions

What is CWE-640?

CWE-640 (CWE-640) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-640?

There are 354 CVE records associated with CWE-640 in our database. Of these, 100 are critical severity, 119 are high severity, and 74 are medium severity.

How can I protect against CWE-640 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-640 using AI-powered security agents.

Detect CWE-640 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-640 vulnerabilities across your infrastructure.

Get Started