The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalat
Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotte
Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX app
A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token
In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the dis
In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password to
Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fi
IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowi
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN
A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code o
A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the
A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an
A vulnerability classified as problematic has been found in HuiRan Host Reseller System up to 2.0.0. Affected is an unkn
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and
A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function send
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerab
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via ins
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xx
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take ov
Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attacker
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier coul
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.
PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component
Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow
AMI Megarac Password reset interception via API
JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-fo
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5
ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locke
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by exec
Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent o
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authenticatio
D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleAction
Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which co
Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token on
A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this i
A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown proces
This issue was addressed with improved state management. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, t
An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.
ZITADEL provides identity infrastructure. In versions 2.37.2 and prior, ZITADEL administrators can enable a setting call
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accident
A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is s
A vulnerability, which was classified as problematic, was found in Byzoro Smart S85F Management Platform V31R02B10-01. A
JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Pr
A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenanc
Frequently Asked Questions
What is CWE-640?
CWE-640 (CWE-640) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-640?
There are 354 CVE records associated with CWE-640 in our database. Of these, 100 are critical severity, 119 are high severity, and 74 are medium severity.
How can I protect against CWE-640 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-640 using AI-powered security agents.
Detect CWE-640 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-640 vulnerabilities across your infrastructure.
Get Started