CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2023-51543 MEDIUM
Metagauss RegistrationMagic <5.2.5.0 - Auth Bypass
CVSS 5.3
CVE-2023-51542 MEDIUM
WPMU DEV Branda <3.4.14 - Auth Bypass
CVSS 5.3
CVE-2023-49741 LOW
Coming soon and Maintenance mode < 3.7.3 - Authentication Bypass via IP Filtering
CVSS 3.7
CVE-2023-48753 MEDIUM
10up Restricted Site Access <7.4.1 - Auth Bypass
CVSS 5.3
CVE-2023-48271 MEDIUM
Maspik - Spam blacklist <0.10.3 - Auth Bypass
CVSS 5.3
CVE-2023-47769 LOW
WP Maintenance <6.1.3 - Auth Bypass
CVSS 3.7
CVE-2023-41134 MEDIUM
Antispam Bee < 2.11.3 - Authentication Bypass via IP Restriction Spoofing
CVSS 5.3
CVE-2023-40332 MEDIUM
WP-PostRatings <= 1.91 - Rating Limit Bypass
CVSS 5.3
CVE-2023-37865 MEDIUM
IP2Location Country Blocker <= 2.29.1 - Authentication Bypass by Spoofing
CVSS 5.3
CVE-2023-50224 MEDIUM KEV
TP-Link TL-WR841N Firmware - Unauthenticated Authentication Bypass via HTTPD Service
CVSS 6.5
CVE-2023-44447 MEDIUM
TP-Link TL-WR902AC Firmware - Unauthenticated Authentication Bypass via httpd Service
CVSS 6.5
CVE-2023-51747 HIGH
Apache James <3.8.1-3.7.5 - SMTP Smuggling
CVSS 7.1
CVE-2023-42889 MEDIUM
macOS 12.0-12.7.1 - Authentication Bypass by Spoofing
CVSS 5.5
CVE-2023-42843 MEDIUM
Safari < 17.1 - Address Bar Spoofing via Inconsistent UI State
CVSS 4.3
CVE-2023-7169 MEDIUM
Snow Inventory Agent < 7.0 - Authentication Bypass via Signature Spoofing
CVSS 6.0
CVE-2023-6044 MEDIUM
Lenovo Vantage - Privilege Escalation
CVSS 6.3
CVE-2023-4566 HIGH
Trust Relationship Inaccuracy - Info Disclosure
CVSS 7.5
CVE-2023-44117 HIGH
Trust Relationship Inaccuracy - Info Disclosure
CVSS 7.5
CVE-2023-4001 MEDIUM
GRUB2 - Authentication Bypass via Duplicate UUID Configuration File
CVSS 6.8
CVE-2023-51350 CRITICAL
ujcms 8.0.2 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 9.8
CVE-2023-41069 MEDIUM
iPadOS < 17.0 - Authentication Bypass via Face ID Spoofing
CVSS 5.5
CVE-2023-49794 MEDIUM
kernelsu < 0.7.1 - Authentication Bypass via Malicious APK Spoofing
CVSS 6.7
CVE-2023-35622 HIGH
Windows Server 2008, 2012, 2016, 2019, 2022, 2022 23H2 - Authentication Bypass via DNS Spoofing
CVSS 7.5
CVE-2023-50463 MEDIUM
Caddy < 0.6.0 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 6.5
CVE-2023-43304 HIGH
PARK DANDAN mini-app - Info Disclosure
CVSS 8.2
Details
Vulnerabilities 637