CWE-640: CWE-640

74
Total CVEs
31
Critical
34
High
8.4
Avg CVSS

Yearly Trend

2026
5
2025
26
2024
13
2023
12
2022
6

Top Affected Vendors

1 Jetbrains 2
2 Schneider Electric 2
3 Password Recovery Project 1
4 Wavlink 1
5 Microweber 1
6 Megafeis 1
7 Alltena 1
8 Misp 1
9 Automatic Question Paper Generator System Project 1
10 Gitlab 1

All CWE-640 CVEs (74)

CVE-2021-29080
8.1

This vulnerability allows unauthenticated attackers to reset passwords on affected NETGEAR routers and WiFi systems. Attackers can gain administrative...

Mar 23, 2021
CVE-2024-42915
8.0

A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to craft malicious password reset links that leak reset tokens. ...

Aug 23, 2024
CVE-2024-2463
8.0

A weak password recovery mechanism in CDeX application versions through 5.7.1 allows attackers to retrieve password reset tokens. This vulnerability e...

Mar 21, 2024
CVE-2023-31287
7.8

This vulnerability allows password reset tokens in Serenity/StartSharp to be reused after initial password reset, remaining valid for 3 hours. Attacke...

Apr 27, 2023
CVE-2021-27654
7.8

This vulnerability allows attackers to bypass local authentication by exploiting forgotten password reset functionality for local accounts. It affects...

Jan 28, 2022
CVE-2025-53704
7.5

CVE-2025-53704 is a weak password reset mechanism vulnerability in the Pivot client application that allows attackers to hijack user accounts by explo...

Dec 4, 2025
CVE-2024-33530
7.5

A logic flaw in Jitsi Meet's lobby feature for password-protected meetings allows unauthorized disclosure of the meeting password when inviting users ...

May 2, 2024
CVE-2023-3222
7.5

This vulnerability allows remote attackers to reset any user's password in Roundcube's Password Recovery plugin version 1.2 by brute-forcing a 6-digit...

Sep 4, 2023
CVE-2023-26615
7.5

CVE-2023-26615 is a password reset vulnerability in D-Link DIR-823G routers that allows unauthenticated attackers to reset the web management interfac...

Jun 28, 2023
CVE-2021-43498
7.5

This vulnerability in ATutor 2.2.4 allows attackers to bypass password reset authentication by manipulating specific HTTP POST parameters in password_...

Apr 8, 2022
CVE-2022-0777
7.5

This vulnerability allows attackers to bypass password recovery mechanisms in Microweber CMS, potentially gaining unauthorized access to user accounts...

Mar 1, 2022
CVE-2021-33321
7.5

This vulnerability allows remote attackers to enumerate user email addresses through Liferay's forgot password functionality due to an insecure defaul...

Aug 3, 2021
CVE-2023-35134
7.4

This vulnerability in Weintek Weincloud v0.13.6 allows attackers to reset passwords using only a valid JWT token for the target account. This affects ...

Jul 19, 2023
CVE-2022-1073
7.3

CVE-2022-1073 is a critical privilege escalation vulnerability in Automatic Question Paper Generator 1.0 that allows remote attackers to gain elevated...

Mar 29, 2022
CVE-2025-61977
7.0

A weak password recovery mechanism in Productivity Suite v4.4.1.19 allows attackers to decrypt encrypted projects by answering just one security quest...

Oct 23, 2025
CVE-2025-62709
6.8

ClipBucket v5.5.2 has a host header injection vulnerability that allows attackers to manipulate password reset links. When the base_url configuration ...

Nov 20, 2025
CVE-2025-56748
6.4

This vulnerability in Creativeitem Academy LMS allows attackers to brute-force password reset tokens due to predictable token generation and lack of r...

Oct 15, 2025
CVE-2026-1325
5.3

This vulnerability allows remote attackers to bypass password recovery mechanisms in Sangfor Operation and Maintenance Security Management System, pot...

Jan 22, 2026
CVE-2025-14696
5.3

This vulnerability allows remote attackers to perform unauthorized password modifications in Shenzhen Sixun Software's Sixun Shanghui Group Business M...

Dec 15, 2025
CVE-2025-13565
5.3

This vulnerability allows unauthenticated attackers to perform weak password recovery attacks on SourceCodester Inventory Management System 1.0. Attac...

Nov 23, 2025
CVE-2025-10322
5.3

This vulnerability in Wavlink WL-WN578W2 routers allows attackers to remotely exploit weak password recovery mechanisms via the /sysinit.html file. At...

Sep 12, 2025
CVE-2025-0331
5.3

This vulnerability in YunzMall allows attackers to remotely bypass password recovery mechanisms through weak password reset functionality. Attackers c...

Jan 9, 2025
CVE-2025-14783
4.3

The Easy Digital Downloads WordPress plugin has an unvalidated redirect vulnerability in all versions up to 3.6.2. Unauthenticated attackers can manip...

Dec 31, 2025
CVE-2025-15398
3.7

This vulnerability in Uasoft Badaso allows attackers to exploit weak password recovery mechanisms in the forgetPassword function. Attackers can potent...

Dec 31, 2025

About CWE-640 (CWE-640)

Our database tracks 74 CVEs classified as CWE-640, with 31 rated critical and 34 rated high severity. The average CVSS score for CWE-640 vulnerabilities is 8.4.

External reference: View CWE-640 on MITRE CWE →

Monitor CWE-640 Vulnerabilities

Get alerted when new CWE-640 CVEs affect your infrastructure.

Start Monitoring Free