CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2025-24628 MEDIUM
BestWebSoft Google Captcha <1.78 - Auth Bypass
CVSS 5.3
CVE-2025-24458 HIGH
JetBrains YouTrack < 2024.3.55417 - Account Takeover via Spoofed Email and Helpdesk Integration
CVSS 7.1
CVE-2025-0442 MEDIUM
Google Chrome < 132.0.6834.83 - UI Spoofing via Payments Implementation
CVSS 6.5
CVE-2025-0440 MEDIUM
Google Chrome < 132.0.6834.83 - UI Spoofing via Fullscreen Implementation
CVSS 6.5
CVE-2024-1524 HIGH
WSO2 API Manager 4.2.0-4.2.0.107 and Identity Server 6.0.0-6.0.0.170 - Authentication Bypass via Silent JIT Provisioning
CVSS 7.7
CVE-2024-8273 HIGH
hypr_server < 10.1.0 - Authentication Bypass by Spoofing
CVSS 8.8
CVE-2024-55210 CRITICAL
TOTVS Framework (Linha Protheus) 12.1.2310 - Authentication Bypass via WebSocket Message
CVSS 9.8
CVE-2024-58127 HIGH
Huawei EMUI - Authentication Bypass via Security Verification Module
CVSS 8.4
CVE-2024-58126 HIGH
Huawei EMUI - Authentication Bypass via Security Verification Module
CVSS 8.4
CVE-2024-58125 HIGH
Huawei EMUI - Authentication Bypass via Security Verification Module
CVSS 8.4
CVE-2024-58124 HIGH
Huawei EMUI and HarmonyOS - Authentication Bypass via Security Verification Module
CVSS 8.4
CVE-2024-54085 CRITICAL KEV
AMI MegaRAC SP-X 12-12.7 - Unauthenticated Authentication Bypass via Redfish Host Interface
CVSS 9.8
CVE-2024-13685 MEDIUM
Admin and Site Enhancements WordPress Plugin < 7.6.10 - Authentication Bypass via IP Header Spoofing
CVSS 5.3
CVE-2024-36557 MEDIUM
Forever KidsWatch Call Me KW50 and KW60 - Authentication Bypass via IMEI Spoofing
CVSS 6.6
CVE-2024-55925 HIGH
Xerox Workplace Suite - Auth Bypass
CVSS 7.5
CVE-2024-13061 CRITICAL
Electronic Official Document Management System - Auth Bypass
CVSS 9.8
CVE-2024-12108 CRITICAL
WhatsUp Gold 23.1.0-24.0.1 - Authentication Bypass via Public API
CVSS 9.6
CVE-2024-54450 CRITICAL
Kurmi Provisioning Suite 7.9.0.33 - Info Disclosure
CVSS 9.4
CVE-2024-55470 HIGH
Oqtane Framework 6.0.0 - Authentication Bypass via EntityID Parameter Spoofing
CVSS 7.5
CVE-2024-55232 MEDIUM
PHPGurukul Online Notes Sharing Management System 1.0 - Insecure Direct Object Reference
CVSS 5.4
CVE-2024-54158 LOW
JetBrains YouTrack <2024.3.52635 - Open Redirect
CVSS 3.5
CVE-2024-50380 HIGH
Snap One OVRC cloud < 7.3 - Authentication Bypass via MAC Address Spoofing
CVE-2024-53862 HIGH
Argo Workflows 3.5.7-3.5.12 - Unauthenticated Workflow Archive Access via Spoofed Token
CVSS 7.5
CVE-2024-36466 HIGH
Zabbix 6.0.0-6.0.31 - Authentication Bypass via Forged zbx_session Cookie
CVSS 8.8
CVE-2024-11701 MEDIUM
Firefox < 133 and Thunderbird < 133 - Authentication Bypass by Spoofing via Address Bar Display
CVSS 4.3
Details
Vulnerabilities 637