CWE-640 忘记口令恢复机制弱 类弱点 110 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-640属于身份验证绕过类漏洞,指应用程序在用户忘记密码时提供的恢复机制存在安全缺陷。攻击者通常利用该弱点,通过猜测简单安全问题、拦截重置链接或暴力破解临时令牌,从而非法重置密码并接管账户。开发者应避免使用可预测的恢复凭据,采用多因素认证、发送一次性动态验证码至受控邮箱或手机,并实施速率限制以增强恢复流程的安全性。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-10169 | School Student Management System 授权问题漏洞 — School Student Management System | 3.7 | Low | 2026-05-31 |
| CVE-2026-7459 | WordPress plugin Simple History 授权问题漏洞 — Simple History – Track, Log, and Audit WordPress Changes | 7.5 | High | 2026-05-30 |
| CVE-2026-35676 | phpMyFAQ 安全漏洞 — phpMyFAQ | 8.2 | High | 2026-05-28 |
| CVE-2026-9609 | FoxCMS 授权问题漏洞 — FoxCMS | 4.7 | Medium | 2026-05-27 |
| CVE-2026-9466 | Tiandy Easy7 Integrated Management Platform 授权问题漏洞 — Easy7 Integrated Management Platform | 5.3 | Medium | 2026-05-25 |
| CVE-2026-42606 | AzuraCast 授权问题漏洞 — AzuraCast | 8.1 | High | 2026-05-09 |
| CVE-2026-7652 | WordPress plugin LatePoint 授权问题漏洞 — LatePoint – Calendar Booking Plugin for Appointments and Events | 5.3 | Medium | 2026-05-09 |
| CVE-2026-29199 | phpBB 授权问题漏洞 — phpBB | 8.2 | - | 2026-05-04 |
| CVE-2026-7554 | D-Link M60 授权问题漏洞 — M60 | 5.6 | Medium | 2026-05-01 |
| CVE-2026-40585 | blueprintUE self-hosted edition 安全漏洞 — blueprintue-self-hosted-edition | 7.4 | High | 2026-04-21 |
| CVE-2026-24467 | OpenAEV 安全漏洞 — openaev | 9.1 | Critical | 2026-04-20 |
| CVE-2025-36579 | Dell Client Platform BIOS 安全漏洞 — Dell Pro 14 Essential PV14250 | 5.1 | Medium | 2026-04-16 |
| CVE-2026-33707 | Chamilo LMS 授权问题漏洞 — chamilo-lms | 9.4 | Critical | 2026-04-10 |
| CVE-2026-4136 | WordPress plugin Membership Plugin – Restrict Content 授权问题漏洞 — Membership Plugin – Restrict Content | 4.3 | Medium | 2026-03-20 |
| CVE-2026-27593 | Statamic 授权问题漏洞 — cms | 9.3 | Critical | 2026-02-24 |
| CVE-2026-2895 | FunAdmin 授权问题漏洞 — funadmin | 3.7 | Low | 2026-02-21 |
| CVE-2026-2564 | Intelbras VIP 3260 Z IA 授权问题漏洞 — VIP 3260 Z IA | 8.1 | High | 2026-02-16 |
| CVE-2020-37158 | AVideo 授权问题漏洞 — AVideo Platform | 5.3 | Medium | 2026-02-11 |
| CVE-2020-37172 | AVideo 授权问题漏洞 — AVideo Platform | 5.3 | Medium | 2026-02-11 |
| CVE-2026-25858 | mall 授权问题漏洞 — mall | 9.1 | Critical | 2026-02-07 |
| CVE-2026-1325 | Sangfor Operation and Maintenance Security Management System 授权问题漏洞 — Operation and Maintenance Security Management System | 5.3 | Medium | 2026-01-22 |
| CVE-2022-50910 | Beehive Forum 授权问题漏洞 — Beehive Forum | 9.8 | Critical | 2026-01-13 |
| CVE-2025-15398 | Badaso 安全漏洞 — badaso | 3.7 | Low | 2025-12-31 |
| CVE-2025-14783 | WordPress plugin Easy Digital Downloads 授权问题漏洞 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy | 4.3 | Medium | 2025-12-31 |
| CVE-2023-53958 | LDAP Tool Box Self Service Password 授权问题漏洞 — LDAP Tool Box Self Service Password | 7.5 | High | 2025-12-19 |
| CVE-2025-14696 | Sixun Shanghui Business Management System 授权问题漏洞 — Sixun Shanghui Group Business Management System | 5.3 | Medium | 2025-12-15 |
| CVE-2025-64113 | Emby Server 授权问题漏洞 — security | 8.1AI | HighAI | 2025-12-09 |
| CVE-2025-53704 | MAXHUB Pivot client application 授权问题漏洞 — Pivot client application | 7.5 | High | 2025-12-04 |
| CVE-2025-13565 | SourceCodester Inventory Management System 授权问题漏洞 — Inventory Management System | 5.3 | Medium | 2025-11-23 |
| CVE-2025-62709 | ClipBucket 授权问题漏洞 — clipbucket-v5 | 6.8 | Medium | 2025-11-20 |
CWE-640(忘记口令恢复机制弱) 是常见的弱点类别,本平台收录该类弱点关联的 110 条 CVE 漏洞。