Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-640

Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

295
Assigned CVEs
108th
Commonality Rank
8.1
Avg CVSS
0.3%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-640 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 26, 2016
9 years ago
Most Recent CVE
Jul 21, 2026
5 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

295 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-7028CRITICAL
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.
Jan 12, 20249.899YESYES
CVE-2019-18818CRITICAL
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
Nov 7, 20199.894NOYES
CVE-2017-7615HIGH
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
Apr 16, 20178.892NOYES
CVE-2024-2862CRITICAL
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
Mar 25, 20249.870NOYES
CVE-2019-19844CRITICAL
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after cas
Dec 18, 20199.860NOYES
CVE-2025-6216CRITICAL
Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations o
Jun 21, 20259.854NOYES
CVE-2025-47646CRITICAL
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery
May 23, 20259.849NOYES
CVE-2017-8295MEDIUM
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a craf
May 4, 20175.946NOYES
CVE-2012-5686CRITICAL
ZPanel 10.0.1 has insufficient entropy for its password reset process.
Feb 4, 20209.843NOYES
CVE-2026-13019CRITICAL
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated
Jul 7, 20269.842NONO
View all 295 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
9%
19%
5.0-5.9
16%
6.0-6.9
19%
26%
7.0-7.9
26%
11%
8.0-8.9
35%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
0.3% of CVEs· 83rd percentile
Metasploit
3 CVEs
1.0% of CVEs· 87th percentile
Nuclei
6 CVEs
2.0% of CVEs· 90th percentile
ExploitDB
10 CVEs
3.4% of CVEs· 93rd percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products