This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
637 vulnerabilities with CWE-290
CVE-2025-24091
MEDIUM
iPadOS < 17.7.3 and < 18.3 - Authentication Bypass via System Notification Spoofing
CVSS 5.5
CVE-2025-28128
HIGH
Mytel Telecom Online Account System 1.0 - Authentication Bypass via OTP Verification Spoofing
CVSS 7.0
CVE-2025-32966
CRITICAL
DataEase < 2.10.8 - Authenticated Remote Code Execution via JDBC Link
CVSS 9.8
CVE-2025-29621
HIGH
RosarioSIS v12.0.0 - Info Disclosure
CVSS 7.3
CVE-2025-32788
MEDIUM
OctoPrint <= 1.10.3 - Authentication Bypass via Login Redirect Spoofing
CVSS 4.3
CVE-2025-2188
HIGH
Honor GameCenter < 16.0.23.304 - Authentication Bypass via Whitelist Mechanism
CVSS 8.1
CVE-2025-32012
HIGH
Jellyfin 10.9.0-10.10.6 - Unauthenticated Denial of Service via IP Spoofing
CVSS 7.5
CVE-2025-32275
MEDIUM
Ays Pro Survey Maker <= 5.1.6.3 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2025-32227
MEDIUM
Asgaros Forum <= 3.0.0 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2025-31170
HIGH
Huawei EMUI - Authentication Bypass via Security Verification Module
CVSS 8.4
CVE-2025-3029
HIGH
Firefox < 128.9.0 and < 137.0 - Authentication Bypass by Spoofing via Unicode URL
CVSS 7.3
CVE-2025-31122
CRITICAL
scratch-coding-hut.github.io <1.0-beta3 - Auth Bypass
CVE-2025-22223
MEDIUM
Spring Security 6.4.0-6.4.3 - Auth Bypass
CVSS 5.3
CVE-2025-30144
MEDIUM
fast-jwt < 5.0.6 - Authentication Bypass via Issuer Claim Spoofing
CVSS 6.5
CVE-2025-30142
HIGH
G-Net Dashcam BB GONX - Auth Bypass
CVSS 8.1
CVE-2025-30110
MEDIUM
IROAD X5 - Authentication Bypass via MAC Address Spoofing
CVSS 6.5
CVE-2025-27616
HIGH
go-vela/server < 0.25.3 and 0.26.0-0.26.3 - Repository Ownership Transfer via Spoofed Webhook Payload
CVSS 8.5
CVE-2025-26696
HIGH
Thunderbird < 128.8.0 and 128.8-128.* and >=136 - Authentication Bypass by Spoofing via OpenPGP Message Type
CVSS 7.0
CVE-2025-27671
CRITICAL
Vasion Print < 20.0.1923 and Virtual Appliance < 22.0.843 - Device Impersonation
CVSS 9.8
CVE-2025-22271
MEDIUM
CyberArk Endpoint Privilege Manager <24.7.1 - SSRF
CVE-2025-25055
MEDIUM
FileMegane >1.0.0.0 <3.4.0.0 - Auth Bypass
CVSS 5.3
CVE-2025-1298
CRITICAL
com.transsion.carlcare - Info Disclosure
CVSS 9.8
CVE-2025-25182
CRITICAL
Stroom <7.2.24, 7.3-beta.22, 7.4.4, 7.5-beta.2 - Auth Bypass
CVSS 9.4
CVE-2025-1104
HIGH
D-Link DHP-W310AV 1.04 - Authentication Bypass by Spoofing
CVSS 7.3
CVE-2025-21415
CRITICAL
Azure AI Face Service - Authentication Bypass by Spoofing
CVSS 9.9
Details
Vulnerabilities
637