Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-640 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 48 | 46 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄█▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 5 · 2026-06 8 · 2026-07 22 · 2026-08 11
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-7028 | 10.0 | 99.9 | KEV | Weak Password Recovery Mechanism for Forgotten Password in GitLab |
| CVE-2026-12571 | 9.8 | 74.3 | — | Authentication Bypass Leading to Account Takeover |
| CVE-2026-11551 | 9.8 | 47.3 | — | Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated… |
| CVE-2026-15689 | 9.8 | 46.4 | — | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset … |
| CVE-2026-7459 | 7.5 | 45.8 | — | Simple History – Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Sub… |
| CVE-2026-56081 | 9.3 | 44.9 | — | Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email |
| CVE-2026-12416 | 9.8 | 44.4 | — | Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset V… |
| CVE-2026-12417 | 9.8 | 37.9 | — | SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset… |
| CVE-2026-13019 | 9.8 | 36.3 | — | Missing Authentication |
| CVE-2023-53958 | 8.6 | 33.0 | — | LDAP Tool Box Self Service Password 1.5.2 Account Takeover via HTTP Host Header |
| CVE-2026-18963 | 9.1 | 32.4 | — | Keycloak-services: keycloak-services: unauthenticated account takeover via reset-creden… |
| CVE-2026-53595 | 9.4 | 30.7 | — | FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on… |
| CVE-2026-50635 | 8.7 | 30.5 | — | LimeSurvey Password Reset Host Header Injection Discloses Reset Token |
| CVE-2026-15155 | 8.8 | 28.9 | — | Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeove… |
| CVE-2026-9466 | 5.5 | 28.4 | — | Tiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword password re… |
| CVE-2026-55207 | 8.8 | 28.2 | — | Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attac… |
| CVE-2026-12949 | 9.8 | 27.0 | — | Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter |
| CVE-2026-61967 | 9.8 | 26.1 | — | WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability |
| CVE-2026-66691 | 9.8 | 26.1 | — | WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability |
| CVE-2026-72856 | 8.6 | 25.7 | — | Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email |
| Vendor | CVEs |
|---|---|
| oracle | 10 |
| esri | 2 |
| pravel | 2 |
| abeverley | 1 |
| apostrophecms | 1 |
| budibase | 1 |
| cap-go | 1 |
| capgo | 1 |
| coollabsio | 1 |
| enhancesoft | 1 |
| eskapism | 1 |
| fossbilling | 1 |
| freescout-help-desk | 1 |
| gitlab | 1 |
| h3c | 1 |