Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-640

MITRE ↗

CWE-640

100
CRITICAL
119
HIGH
74
MEDIUM
14
LOW
313 CVEs · Page 5/7
9.8
CVE-2022-27157

pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.

9.8
CVE-2022-37300

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized ac

9.8
CVE-2022-44004

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthentica

9.8
CVE-2022-3485

In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password

9.8
CVE-2022-47377

Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivilege

8.8
CVE-2022-29933

Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the a

8.1
CVE-2022-29174

countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4,

7.8
CVE-2021-27654

Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.

7.5
CVE-2022-0777

Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.

7.5
CVE-2021-43498

An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden,

7.5
CVE-2020-12067

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed b

7.3
CVE-2022-1073

A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads t

6.8
CVE-2022-22691

The password reset component deployed within Umbraco uses the hostname supplied within the request host header when buil

6.5
CVE-2021-44839

An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the accoun

6.4
CVE-2022-24892

Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple

5.5
CVE-2022-23172

An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would

5.3
CVE-2022-23619

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver

5.3
CVE-2022-34530

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames v

9.8
CVE-2021-22731

Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSES

9.8
CVE-2021-28293

Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Passw

9.8
CVE-2021-22763

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic

9.8
CVE-2021-36209

In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.

9.1
CVE-2021-25323

The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the p

8.8
CVE-2021-31912

In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.

8.8
CVE-2021-25957

In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low

8.1
CVE-2021-29080

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10

8.1
CVE-2021-28128

In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password

8.0
CVE-2021-25961

In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password

7.5
CVE-2021-33321

Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attacker

7.5
CVE-2021-36708

In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the

7.5
CVE-2021-44037

Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.

6.1
CVE-2021-37541

In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.

5.4
CVE-2021-36804

Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy

5.3
CVE-2021-37693

Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when

5.3
CVE-2021-36095

Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS

5.1
CVE-2020-5361

Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist

4.4
CVE-2021-39919

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all

2.9
CVE-2021-39899

In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s passwor

9.8
CVE-2020-7245

Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arb

9.8
CVE-2012-5618

Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

9.8
CVE-2012-5686

ZPanel 10.0.1 has insufficient entropy for its password reset process.

9.8
CVE-2020-25105

eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilit

9.8
CVE-2020-27179

konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset to

9.1
CVE-2019-6560

In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the

8.8
CVE-2019-20004

An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain

8.8
CVE-2020-25728

The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malici

7.5
CVE-2009-5025

A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a p

7.5
CVE-2020-14015

An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation cod

7.5
CVE-2020-27408

OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow

7.3
CVE-2020-28186

Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functi

Frequently Asked Questions

What is CWE-640?

CWE-640 (CWE-640) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-640?

There are 354 CVE records associated with CWE-640 in our database. Of these, 100 are critical severity, 119 are high severity, and 74 are medium severity.

How can I protect against CWE-640 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-640 using AI-powered security agents.

Detect CWE-640 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-640 vulnerabilities across your infrastructure.

Get Started