CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2025-24091 MEDIUM
iPadOS < 17.7.3 and < 18.3 - Authentication Bypass via System Notification Spoofing
CVSS 5.5
CVE-2025-28128 HIGH
Mytel Telecom Online Account System 1.0 - Authentication Bypass via OTP Verification Spoofing
CVSS 7.0
CVE-2025-32966 CRITICAL
DataEase < 2.10.8 - Authenticated Remote Code Execution via JDBC Link
CVSS 9.8
CVE-2025-29621 HIGH
RosarioSIS v12.0.0 - Info Disclosure
CVSS 7.3
CVE-2025-32788 MEDIUM
OctoPrint <= 1.10.3 - Authentication Bypass via Login Redirect Spoofing
CVSS 4.3
CVE-2025-2188 HIGH
Honor GameCenter < 16.0.23.304 - Authentication Bypass via Whitelist Mechanism
CVSS 8.1
CVE-2025-32012 HIGH
Jellyfin 10.9.0-10.10.6 - Unauthenticated Denial of Service via IP Spoofing
CVSS 7.5
CVE-2025-32275 MEDIUM
Ays Pro Survey Maker <= 5.1.6.3 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2025-32227 MEDIUM
Asgaros Forum <= 3.0.0 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2025-31170 HIGH
Huawei EMUI - Authentication Bypass via Security Verification Module
CVSS 8.4
CVE-2025-3029 HIGH
Firefox < 128.9.0 and < 137.0 - Authentication Bypass by Spoofing via Unicode URL
CVSS 7.3
CVE-2025-31122 CRITICAL
scratch-coding-hut.github.io <1.0-beta3 - Auth Bypass
CVE-2025-22223 MEDIUM
Spring Security 6.4.0-6.4.3 - Auth Bypass
CVSS 5.3
CVE-2025-30144 MEDIUM
fast-jwt < 5.0.6 - Authentication Bypass via Issuer Claim Spoofing
CVSS 6.5
CVE-2025-30142 HIGH
G-Net Dashcam BB GONX - Auth Bypass
CVSS 8.1
CVE-2025-30110 MEDIUM
IROAD X5 - Authentication Bypass via MAC Address Spoofing
CVSS 6.5
CVE-2025-27616 HIGH
go-vela/server < 0.25.3 and 0.26.0-0.26.3 - Repository Ownership Transfer via Spoofed Webhook Payload
CVSS 8.5
CVE-2025-26696 HIGH
Thunderbird < 128.8.0 and 128.8-128.* and >=136 - Authentication Bypass by Spoofing via OpenPGP Message Type
CVSS 7.0
CVE-2025-27671 CRITICAL
Vasion Print < 20.0.1923 and Virtual Appliance < 22.0.843 - Device Impersonation
CVSS 9.8
CVE-2025-22271 MEDIUM
CyberArk Endpoint Privilege Manager <24.7.1 - SSRF
CVE-2025-25055 MEDIUM
FileMegane >1.0.0.0 <3.4.0.0 - Auth Bypass
CVSS 5.3
CVE-2025-1298 CRITICAL
com.transsion.carlcare - Info Disclosure
CVSS 9.8
CVE-2025-25182 CRITICAL
Stroom <7.2.24, 7.3-beta.22, 7.4.4, 7.5-beta.2 - Auth Bypass
CVSS 9.4
CVE-2025-1104 HIGH
D-Link DHP-W310AV 1.04 - Authentication Bypass by Spoofing
CVSS 7.3
CVE-2025-21415 CRITICAL
Azure AI Face Service - Authentication Bypass by Spoofing
CVSS 9.9
Details
Vulnerabilities 637