This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
637 vulnerabilities with CWE-290
CVE-2024-28228
MEDIUM
JetBrains YouTrack < 2024.1.25893 - Authentication Bypass via HelpDesk Comment Spoofing
CVSS 5.3
CVE-2024-22457
HIGH
Dell Secure Connect Gateway 5.20 - Auth Bypass
CVSS 7.1
CVE-2024-1555
HIGH
Firefox < 123.0 - SameSite Cookie Bypass via firefox:// Protocol Handler
CVSS 8.3
CVE-2024-1547
MEDIUM
Firefox < 123 and ESR < 115.8 - Authentication Bypass by Spoofing via Alert Dialog
CVSS 6.5
CVE-2024-21494
MEDIUM
greenpau/caddy-security - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 5.4
CVE-2024-23674
CRITICAL
German National Identity Card <2024-02-15 - Auth Bypass
CVSS 9.6
CVE-2024-22520
HIGH
Dronetag Drone Scanner <1.5.2 - Privilege Escalation
CVSS 8.2
CVE-2024-22519
HIGH
OpenDroneID OSM 3.5.1 - Authentication Bypass by Spoofing via Crafted Data Packets
CVSS 8.2
CVE-2024-23832
CRITICAL
Mastodon < 3.5.17, 4.0.x < 4.0.13, 4.1.x < 4.1.13, 4.2.x < 4.2.5 - Authentication Bypass via LDAP Origin Validation
CVSS 9.4
CVE-2024-0454
MEDIUM
ELAN Match-on-Chip FPR - Info Disclosure
CVSS 6.0
CVE-2024-20674
HIGH
Windows Kerberos - Privilege Escalation
CVSS 8.8
CVE-2023-41591
CRITICAL
Open Network Foundation ONOS <2.7.0 - Privilege Escalation
CVSS 9.8
CVE-2023-5616
MEDIUM
gnome-control-center 1.3-1.3.36.5 - Authentication Bypass via SSH Remote Login Status Mismanagement
CVSS 4.9
CVE-2023-51327
MEDIUM
PHPJabbers Cleaning Business Software v1.0 - DoS
CVSS 6.5
CVE-2023-51326
MEDIUM
PHPJabbers Cleaning Business Software <1.0 - DoS
CVSS 6.5
CVE-2023-51323
MEDIUM
PHPJabbers Shared Asset Booking System <1.0 - DoS
CVSS 6.5
CVE-2023-51321
MEDIUM
PHPJabbers Night Club Booking Software v1.0 - DoS
CVSS 6.5
CVE-2023-41133
MEDIUM
Secure Admin IP < 2.0 - Authentication Bypass via IP Spoofing
CVSS 5.3
CVE-2023-30464
HIGH
CoreDNS < 1.10.1 - DNS Cache Poisoning via Birthday Attack
CVSS 7.5
CVE-2023-28452
HIGH
CoreDNS < 1.10.1 and < 1.11.0 - Denial of Service via Spoofed DNS Response
CVSS 7.5
CVE-2023-48396
CRITICAL
Apache SeaTunnel <1.0.1 - Auth Bypass
CVSS 9.1
CVE-2023-40702
HIGH
PingOne MFA Integration Kit - Auth Bypass
CVE-2023-40356
HIGH
PingOne MFA Integration Kit - Privilege Escalation
CVE-2023-52176
MEDIUM
miniorange Malware Scanner <4.7.1 - Auth Bypass
CVSS 5.3
CVE-2023-51667
MEDIUM
FeedbackWP Rate my Post - Auth Bypass
CVSS 5.3
Details
Vulnerabilities
637