This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
637 vulnerabilities with CWE-290
CVE-2025-24628
MEDIUM
BestWebSoft Google Captcha <1.78 - Auth Bypass
CVSS 5.3
CVE-2025-24458
HIGH
JetBrains YouTrack < 2024.3.55417 - Account Takeover via Spoofed Email and Helpdesk Integration
CVSS 7.1
CVE-2025-0442
MEDIUM
Google Chrome < 132.0.6834.83 - UI Spoofing via Payments Implementation
CVSS 6.5
CVE-2025-0440
MEDIUM
Google Chrome < 132.0.6834.83 - UI Spoofing via Fullscreen Implementation
CVSS 6.5
CVE-2024-1524
HIGH
WSO2 API Manager 4.2.0-4.2.0.107 and Identity Server 6.0.0-6.0.0.170 - Authentication Bypass via Silent JIT Provisioning
CVSS 7.7
CVE-2024-8273
HIGH
hypr_server < 10.1.0 - Authentication Bypass by Spoofing
CVSS 8.8
CVE-2024-55210
CRITICAL
TOTVS Framework (Linha Protheus) 12.1.2310 - Authentication Bypass via WebSocket Message
CVSS 9.8
CVE-2024-58127
HIGH
Huawei EMUI - Authentication Bypass via Security Verification Module
CVSS 8.4
CVE-2024-58126
HIGH
Huawei EMUI - Authentication Bypass via Security Verification Module
CVSS 8.4
CVE-2024-58125
HIGH
Huawei EMUI - Authentication Bypass via Security Verification Module
CVSS 8.4
CVE-2024-58124
HIGH
Huawei EMUI and HarmonyOS - Authentication Bypass via Security Verification Module
CVSS 8.4
CVE-2024-54085
CRITICAL
KEV
AMI MegaRAC SP-X 12-12.7 - Unauthenticated Authentication Bypass via Redfish Host Interface
CVSS 9.8
CVE-2024-13685
MEDIUM
Admin and Site Enhancements WordPress Plugin < 7.6.10 - Authentication Bypass via IP Header Spoofing
CVSS 5.3
CVE-2024-36557
MEDIUM
Forever KidsWatch Call Me KW50 and KW60 - Authentication Bypass via IMEI Spoofing
CVSS 6.6
CVE-2024-55925
HIGH
Xerox Workplace Suite - Auth Bypass
CVSS 7.5
CVE-2024-13061
CRITICAL
Electronic Official Document Management System - Auth Bypass
CVSS 9.8
CVE-2024-12108
CRITICAL
WhatsUp Gold 23.1.0-24.0.1 - Authentication Bypass via Public API
CVSS 9.6
CVE-2024-54450
CRITICAL
Kurmi Provisioning Suite 7.9.0.33 - Info Disclosure
CVSS 9.4
CVE-2024-55470
HIGH
Oqtane Framework 6.0.0 - Authentication Bypass via EntityID Parameter Spoofing
CVSS 7.5
CVE-2024-55232
MEDIUM
PHPGurukul Online Notes Sharing Management System 1.0 - Insecure Direct Object Reference
CVSS 5.4
CVE-2024-54158
LOW
JetBrains YouTrack <2024.3.52635 - Open Redirect
CVSS 3.5
CVE-2024-50380
HIGH
Snap One OVRC cloud < 7.3 - Authentication Bypass via MAC Address Spoofing
CVE-2024-53862
HIGH
Argo Workflows 3.5.7-3.5.12 - Unauthenticated Workflow Archive Access via Spoofed Token
CVSS 7.5
CVE-2024-36466
HIGH
Zabbix 6.0.0-6.0.31 - Authentication Bypass via Forged zbx_session Cookie
CVSS 8.8
CVE-2024-11701
MEDIUM
Firefox < 133 and Thunderbird < 133 - Authentication Bypass by Spoofing via Address Bar Display
CVSS 4.3
Details
Vulnerabilities
637