Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-640
Weakness type CWE-640 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 68 | 65 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▃▄█▆▅▁
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 2 · 2026-03 0 · 2026-04 0 · 2026-05 5 · 2026-06 8 · 2026-07 22 · 2026-08 15 · 2026-09 12 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-7028 | 10.0 | 99.9 | KEV | Weak Password Recovery Mechanism for Forgotten Password in GitLab |
| CVE-2026-19632 | 9.8 | 95.1 | — | TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password … |
| CVE-2026-12571 | 9.8 | 88.0 | — | Authentication Bypass Leading to Account Takeover |
| CVE-2026-18963 | 9.1 | 87.6 | — | Keycloak-services: keycloak-services: unauthenticated account takeover via reset-creden… |
| CVE-2026-53595 | 9.4 | 79.5 | — | FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on… |
| CVE-2026-13019 | 9.8 | 56.6 | — | Missing Authentication |
| CVE-2026-15689 | 9.8 | 56.3 | — | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset … |
| CVE-2023-43902 | 9.8 | 56.0 | — | — |
| CVE-2026-12417 | 9.8 | 55.8 | — | SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset… |
| CVE-2026-71625 | 9.8 | 53.0 | — | — |
| CVE-2020-37172 | 8.5 | 52.2 | — | AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset) |
| CVE-2026-77264 | 9.8 | 51.8 | — | Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_trans… |
| CVE-2026-12416 | 9.8 | 50.4 | — | Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset V… |
| CVE-2026-15155 | 8.8 | 50.3 | — | Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeove… |
| CVE-2026-55207 | 8.8 | 50.1 | — | Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attac… |
| CVE-2026-50635 | 8.7 | 49.9 | — | LimeSurvey Password Reset Host Header Injection Discloses Reset Token |
| CVE-2026-84699 | 9.3 | 48.3 | — | Team Password Manager before 14.184.308 Authentication Bypass in Password Reset |
| CVE-2026-11551 | 9.8 | 47.9 | — | Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated… |
| CVE-2026-86260 | 5.5 | 46.6 | — | sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverifi… |
| CVE-2026-7459 | 7.5 | 46.0 | — | Simple History – Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Sub… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| oracle | 10 |
| avideo | 2 |
| esri | 2 |
| pravel | 2 |
| 101gen | 1 |
| abeverley | 1 |
| alinto | 1 |
| ankaref innovation and technology | 1 |
| apostrophecms | 1 |
| beetel | 1 |
| budibase | 1 |
| cap-go | 1 |
| capgo | 1 |
| concrete cms | 1 |
| coollabsio | 1 |