Skip to main content

CWE archive

CWE-640 CVEs

Programmatic archive

300 CVEs tagged with CWE-64089 Critical, 122 High, 74 Medium, 14 Low, 1 Unrated.

CVE-2026-18363

Published Jul 30, 2026

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the appli…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-64635

Published Jul 30, 2026

Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the gene…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62517

Published Jul 21, 2026

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Di…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62486

Published Jul 21, 2026

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Di…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-61143

Published Jul 21, 2026

Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-61049

Published Jul 21, 2026

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Di…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-60658

Published Jul 21, 2026

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60646

Published Jul 21, 2026

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53595

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenC…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-56308

Published Jul 12, 2026

Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. An attacker with access to a…

CVSS 8.4 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-15479

Published Jul 12, 2026

A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-15155

Published Jul 11, 2026

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all v…

CVSS 8.8 · High
evidence mentions
10
Buzz score
35.5

CVE-2026-7655

Published Jul 11, 2026

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly valida…

CVSS 8.1 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-55207

Published Jul 9, 2026

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pim…

CVSS 8.8 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-34198

Published Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the TrustProxies middleware trusts all proxies ($proxi…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-53646

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `ClientPasswordReset` record already exists for a client (from a p…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-53904

Published Jul 1, 2026

MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidates previously set password as w…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-37106

Published Jun 30, 2026

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier b…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2026-12417

Published Jun 24, 2026

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
29.4

CVE-2026-12416

Published Jun 24, 2026

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_cha…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
29.4
Showing 1-25 of 300 CVEsPage 1 of 12