CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2024-42364 MEDIUM
Homepage 0.9.1 - Unauthenticated Information Disclosure via DNS Rebinding
CVSS 6.5
CVE-2024-38807 MEDIUM
Spring Boot Loader 2.7.0-2.7.21, 3.0.0-3.0.16, 3.1.0-3.1.12, 3.2.0-3.2.8, 3.3.0-3.3.2 - Signature Forgery
CVSS 6.3
CVE-2024-7981 MEDIUM
Google Chrome < 128.0.6613.84 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2024-35539 MEDIUM
Typecho 1.3.0 - Race Condition in Post Commenting Function
CVSS 6.5
CVE-2024-35538 MEDIUM
Typecho 1.3.0 - Client IP Spoofing via X-Forwarded-For or Client-Ip Headers
CVSS 5.3
CVE-2024-41432 MEDIUM
Likeshop < 2.5.7.20210811 - IP Spoofing via X-Forwarded or Client-IP Header
CVSS 5.3
CVE-2024-27853 MEDIUM
macOS Sonoma <14.4 - Info Disclosure
CVSS 4.4
CVE-2024-41107 HIGH
Apache CloudStack 4.5.0-4.18.2.1 - Authentication Bypass via SAML Response Spoofing
CVSS 8.1
CVE-2024-37430 MEDIUM
Patreon WordPress <1.9.0 - Auth Bypass
CVSS 5.3
CVE-2024-6163 MEDIUM
Checkmk <2.3.0p10-2.0.0p39 - Auth Bypass
CVSS 5.3
CVE-2024-37082 CRITICAL
haproxy-boshrelease < 0.299.0 - mTLS Authentication Bypass via Crafted HTTP Requests
CVSS 9.1
CVE-2024-39350 HIGH
Synology BC500 and TC500 Firmware < 1.0.7-0298 - Authentication Bypass via RTSP Spoofing
CVSS 7.5
CVE-2024-31802 MEDIUM
DESIGNA ABACUS v.18 and before - Authentication Bypass via Crafted QR Code
CVSS 6.3
CVE-2024-4846 MEDIUM
Devolutions Server < 2024.1.15.0 - Authenticated Authentication Bypass via 2FA Spoofing
CVSS 6.3
CVE-2024-39337 MEDIUM
Click Studios Passwordstate Core <9.8.9858 - Auth Bypass
CVSS 6.5
CVE-2024-21518 HIGH
OpenCart >= 4.0.0.0 - Path Traversal via Marketplace Installer Zip Slip
CVSS 7.2
CVE-2024-30058 MEDIUM
Microsoft Edge Chromium < 126.0.2592.56 - Spoofing
CVSS 5.4
CVE-2024-36588 MEDIUM
Annonshop.app - Info Disclosure
CVSS 6.5
CVE-2024-5812 LOW
Beyondtrust Beyondinsight Password Safe < 23.2.0.1293 - Authentication Bypass by Spoofing
CVSS 3.3
CVE-2024-35749 LOW
Acurax Under Construction / Maintenance Mode < 2.6 - Authentication Bypass by Spoofing
CVSS 3.7
CVE-2024-5037 HIGH
Red Hat OpenShift Container Platform 4.12-4.16 - Authentication Bypass via Forged JWT Token
CVSS 7.5
CVE-2024-4358 CRITICAL KEV
Telerik Report Server Auth Bypass and Deserialization RCE
CVSS 9.8
CVE-2024-20363 MEDIUM
Cisco Firepower Threat Defense Snort IPS Engine Unauthenticated Rule Bypass via HTTP Packets
CVSS 5.8
CVE-2024-32827 MEDIUM
RafflePress Giveaways and Contests <1.12.7 - Auth Bypass
CVSS 5.3
CVE-2024-32786 MEDIUM
Royal Elementor Addons < 1.3.93 - Authentication Bypass via IP Spoofing
CVSS 5.3
Details
Vulnerabilities 637