CWE-640

High likelihood

Weak Password Recovery Mechanism for Forgotten Password

Parent: CWE-1390 - Weak Authentication

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

300 vulnerabilities with CWE-640
CVE-2026-18363 CRITICAL
Weak password recovery mechanism in osTicket by Enhancesoft LLC
CVE-2026-64635 MEDIUM
Veeam Service Provider Console < 9.2 - Weak Password Recovery Mechanism for Forgotten Password
CVSS 5.3
CVE-2026-62517 MEDIUM
Oracle Production Scheduling < 12.2.15 - Insufficient Verification of Data Authenticity
CVSS 5.3
CVE-2026-62486 MEDIUM
Oracle Contracts Integration < 12.2.15 - Denial of Service
CVSS 5.0
CVE-2026-61181 HIGH
Oracle Agile PLM for Process 6.2.4: Authenticated Data Access/Modification via Product Quality Mgmt
CVSS 7.6
CVE-2026-61143 MEDIUM
Oracle Communications Convergent Charging Controller 15.0.0.0.0/15.2.0.0.0 Auth Bypass RCE via Prov IF
CVSS 6.4
CVE-2026-61049 HIGH
Oracle Production Scheduling 12.2.3-12.2.15 Unauth RCE via Physical Network Access & User Interaction
CVSS 7.1
CVE-2026-60658 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 7.5
CVE-2026-60650 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60648 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60646 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-53595 CRITICAL
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
CVSS 9.4
CVE-2026-56308 HIGH
Capgo - Insufficient Authentication in Email Change Endpoint
CVSS 7.3
CVE-2026-15479 HIGH
H3C NX15 Administrator Password Modification Endpoint modify change_passwd password recovery
CVSS 7.3
CVE-2026-15155 HIGH
Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection
CVSS 8.8
CVE-2026-7655 HIGH
SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook
CVSS 8.1
CVE-2026-55207 HIGH
Pimcore < 2025.4.6/2026.1.6 - Unauthenticated Account Takeover
CVSS 8.8
CVE-2026-13020 HIGH
Weak Password Recovery Mechanism in Portal for ArcGIS
CVSS 8.1
CVE-2026-13019 CRITICAL
Esri Portal for ArcGIS <= 12.1 - Unauthenticated API Access
CVSS 9.8
CVE-2026-34198 MEDIUM
Coolify: Password reset link poisoning via X-Forwarded-Host header spoofing
CVSS 5.3
CVE-2026-53646 HIGH
FOSSBilling: Client password reset token reuse allows persistent account takeover
CVE-2026-53904 HIGH
Mycomplianceoffice Mco < 25.3.3.1 - Denial of Service
CVSS 7.1
CVE-2026-37106 CRITICAL
DokuWiki 2025-05-14b - Remote Code Execution via Register Function in auth.php
CVSS 9.8
CVE-2026-12417 CRITICAL
SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover
CVSS 9.8
CVE-2026-12416 CRITICAL
Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter
CVSS 9.8
Details
Vulnerabilities 300
Exploit Likelihood High