An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a
Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the reg
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-
A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out inf
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords v
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for re
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Clo
Frequently Asked Questions
What is CWE-640?
CWE-640 (CWE-640) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-640?
There are 354 CVE records associated with CWE-640 in our database. Of these, 100 are critical severity, 119 are high severity, and 74 are medium severity.
How can I protect against CWE-640 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-640 using AI-powered security agents.
Detect CWE-640 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-640 vulnerabilities across your infrastructure.
Get Started