This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
576 vulnerabilities with CWE-290
CVE-2022-38164
MEDIUM
F-Secure SAFE < 19.0 - URL Spoofing via Phishing Attack
CVSS 6.5
CVE-2022-38712
MEDIUM
IBM WebSphere Application Server - SOAPAction Spoofing
CVSS 5.9
CVE-2022-3337
MEDIUM
WARP mobile client - Info Disclosure
CVSS 6.7
CVE-2022-42983
HIGH
anji-plus AJ-Report 0.9.8.6 - Authentication Bypass via JWT Token Spoofing
CVSS 8.8
CVE-2022-0030
HIGH
PAN-OS 8.1.0-8.1.23 - Authentication Bypass via Web Interface Impersonation
CVSS 8.1
CVE-2022-35770
MEDIUM
Windows NTLM Spoofing - Privilege Escalation
CVSS 6.5
CVE-2022-34689
HIGH
Windows CryptoAPI - Authentication Bypass by Spoofing
CVSS 7.5
CVE-2022-39227
CRITICAL
python-jwt < 3.3.4 - Authentication Bypass by Spoofing
CVSS 9.1
CVE-2022-23949
HIGH
Keylime < 6.3.0 - Log Spoofing via Unsanitized UUID
CVSS 7.5
CVE-2022-35957
MEDIUM
Grafana <9.1.6, 8.5.13 - Privilege Escalation
CVSS 6.6
CVE-2022-37709
MEDIUM
Tesla Model 3 Firmware V11.0(2022.4.5.1 6b701552d7a6) - Authentication Bypass via BLE Phone Key Spoofing
CVSS 5.3
CVE-2022-31149
HIGH
ActivityWatch < 0.12.0b2 - Authentication Bypass via DNS Rebinding
CVSS 8.8
CVE-2022-32744
HIGH
Samba 4.3.0-4.14.13 - Authentication Bypass via Kpasswd Request Spoofing
CVSS 8.8
CVE-2022-33991
MEDIUM
dproxy-nexgen - DNSSEC Protection Bypass via CD Bit Spoofing
CVSS 5.3
CVE-2022-34716
MEDIUM
.NET 6.0.0-6.0.7 and .NET Core 3.1-3.1.27 - Authentication Bypass by Spoofing
CVSS 5.9
CVE-2022-2324
HIGH
SonicWall Hosted Email Security <10.0.17.7319 - Info Disclosure
CVSS 7.5
CVE-2022-35629
MEDIUM
Velociraptor < 0.6.5-2 - Authentication Bypass by Client ID Spoofing
CVSS 5.4
CVE-2022-30319
HIGH
Honeywell Saia PG5 Controls Suite - Authentication Bypass via S-Bus UDP Spoofing
CVSS 8.1
CVE-2022-2310
CRITICAL
Skyhigh SWG <10.2.12-11.2.1 - Auth Bypass
CVSS 10.0
CVE-2022-1495
MEDIUM
Google Chrome < 101.0.4951.41 - Authentication Bypass by Spoofing via APK Downloads Dialog
CVSS 4.3
CVE-2022-1307
MEDIUM
Google Chrome < 100.0.4896.88 - URL Spoofing via Full Screen Mode
CVSS 4.3
CVE-2022-1306
MEDIUM
Google Chrome < 100.0.4896.88 - URL Spoofing via Omnibox Manipulation
CVSS 4.3
CVE-2022-1129
MEDIUM
Google Chrome < 100.0.4896.60 - URL Spoofing via Full Screen Mode
CVSS 6.5
CVE-2022-2368
MEDIUM
microweber < 1.2.20 - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2022-22476
HIGH
IBM WebSphere App Server <22.0.0.7 - Auth Bypass
CVSS 8.8
Details
Vulnerabilities
576