pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized ac
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthentica
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivilege
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the a
countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4,
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden,
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed b
A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads t
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when buil
An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the accoun
Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames v
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSES
Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Passw
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the p
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low
Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attacker
In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when
Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS
Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist
In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all
In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s passwor
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arb
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
ZPanel 10.0.1 has insufficient entropy for its password reset process.
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilit
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset to
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malici
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a p
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation cod
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functi
Frequently Asked Questions
What is CWE-640?
CWE-640 (CWE-640) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-640?
There are 354 CVE records associated with CWE-640 in our database. Of these, 100 are critical severity, 119 are high severity, and 74 are medium severity.
How can I protect against CWE-640 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-640 using AI-powered security agents.
Detect CWE-640 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-640 vulnerabilities across your infrastructure.
Get Started