CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2024-32708 LOW
helderk Maintenance Mode <3.0.1 - Auth Bypass
CVSS 3.7
CVE-2024-33917 MEDIUM
WTI Like Post <= 1.4.6 - Authentication Bypass by Spoofing
CVSS 5.3
CVE-2024-30522 MEDIUM
Newsletter < 8.2.0 - IP Blacklist Bypass via Spoofing
CVSS 5.3
CVE-2024-30480 LOW
Pippin Williamson CGC Maintenance Mode - Auth Bypass
CVSS 3.7
CVE-2024-30479 MEDIUM
LionScripts IP Blocker Lite - Auth Bypass
CVSS 5.3
CVE-2024-25906 MEDIUM
WP Happy Coders Comments Like Dislike <1.2.2 - Auth Bypass
CVSS 4.3
CVE-2024-25595 MEDIUM
WPMU DEV Defender <4.4.1 - Auth Bypass
CVSS 5.3
CVE-2024-22139 LOW
WordPress Manutenção <1.0.6 - Auth Bypass
CVSS 3.7
CVE-2024-21746 MEDIUM
Wp Ultimate Review <= 2.3.6 - Authentication Bypass by Spoofing
CVSS 5.3
CVE-2024-32977 HIGH
OctoPrint <= 1.10.0 - Unauthenticated Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 7.1
CVE-2024-34397 MEDIUM
GNOME GLib <2.78.5, 2.79.x, 2.80.x - Info Disclosure
CVSS 5.2
CVE-2024-34145 HIGH
Jenkins Script Security Plugin <1335.vf07d9ce377a_e - RCE
CVSS 8.8
CVE-2024-1347 MEDIUM
GitLab < 16.9.6, 16.10 < 16.10.4, 16.11 < 16.11.1 - Authentication Bypass via Crafted Email Address
CVSS 4.3
CVE-2024-33531 HIGH
cdbattags lua-resty-jwt 0.2.3 - Authentication Bypass via JWT enc Header Spoofing
CVSS 8.1
CVE-2024-27349 CRITICAL
Apache HugeGraph-Server <1.3.0 - Auth Bypass
CVSS 9.1
CVE-2024-3843 MEDIUM
Google Chrome < 124.0.6367.60 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2024-31784 MEDIUM
Typora < 1.8.10 - Authentication Bypass and Arbitrary Code Execution via src Component
CVSS 6.1
CVE-2024-23558 MEDIUM
HCL DevOps Deploy 8.0.0.0-8.0.0.9 and HCL Launch 7.0.0.0-7.0.5.1 - Authenticated Session Fixation via Incomplete Logout
CVSS 6.3
CVE-2024-31863 MEDIUM
Apache Zeppelin <0.11.0 - Auth Bypass
CVSS 5.3
CVE-2024-30191 HIGH
Siemens SCALANCE W Series - Authentication Bypass by Spoofing via Security Context Override
CVSS 8.4
CVE-2024-30190 MEDIUM
Siemens SCALANCE W Series - Denial of Service via Power-Saving Mechanism Abuse
CVSS 6.1
CVE-2024-30189 MEDIUM
Siemens SCALANCE W Series - Authentication Bypass by Spoofing via Wi-Fi Frame Queue Leak
CVSS 6.1
CVE-2024-29006 CRITICAL
Apache CloudStack 4.11.0.0-4.18.1.0 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 9.8
CVE-2024-31008 MEDIUM
WUZHICMS 4.1.0 - Authentication Bypass via Captcha Logic Flaw
CVSS 6.5
CVE-2024-22092 HIGH
OpenHarmony 3.2-3.2.4 - Authentication Bypass via App Installation Permission Spoofing
CVSS 7.7
Details
Vulnerabilities 637