This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
637 vulnerabilities with CWE-290
CVE-2021-28810
HIGH
Roon Server < 2021-05-18 - Authentication Bypass
CVSS 7.5
CVE-2021-20278
MEDIUM
Kiali < 1.31.0 - Authentication Bypass via OpenID Implicit Flow
CVSS 6.5
CVE-2021-31209
MEDIUM
Microsoft Exchange Server - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2021-31195
MEDIUM
Microsoft Exchange Server - Remote Code Execution
CVSS 6.5
CVE-2021-31172
HIGH
Microsoft SharePoint Server - Authentication Bypass by Spoofing
CVSS 7.1
CVE-2021-28478
HIGH
Microsoft SharePoint Server - Authentication Bypass by Spoofing
CVSS 7.6
CVE-2021-26418
MEDIUM
Microsoft SharePoint Server - Authentication Bypass by Spoofing
CVSS 4.6
CVE-2021-29441
HIGH
Nacos < 1.4.1 - Authentication Bypass via User-Agent Spoofing
CVSS 8.6
CVE-2021-21216
MEDIUM
Google Chrome < 90.0.4430.72 - Authentication Bypass by Spoofing via Autofill Security UI
CVSS 6.5
CVE-2021-21215
MEDIUM
Google Chrome < 90.0.4430.72 - Authentication Bypass by Spoofing via Autofill
CVSS 6.5
CVE-2021-0232
HIGH
Juniper Paragon Active Assurance Control Center < 2.35.6 - Improper Access Control
CVSS 7.4
CVE-2021-21492
MEDIUM
SAP NetWeaver Application Server Java - Content Spoofing via Logon Group URL Validation
CVSS 4.3
CVE-2021-22890
LOW
curl/libcurl 7.63.0-7.75.0 - HTTPS Proxy MITM via TLS Session Tickets
CVSS 3.7
CVE-2021-23984
MEDIUM
Firefox < 87.0 and Firefox ESR < 78.9 - Authentication Bypass by Spoofing via Popup Window
CVSS 6.5
CVE-2021-21310
MEDIUM
next-auth < 3.3.0 - Authentication Bypass via Prisma Adapter Email Token Verification
CVSS 6.1
CVE-2021-21134
MEDIUM
Google Chrome < 88.0.4324.96 - Security UI Spoofing via Page Info
CVSS 6.5
CVE-2021-1677
MEDIUM
Azure Kubernetes Service - Authentication Bypass via Azure Active Directory Pod Identity Spoofing
CVSS 5.5
CVE-2020-37056
CRITICAL
Crystal Shard http-protection 0.2.0 - SSRF
CVSS 9.8
CVE-2020-6158
MEDIUM
Opera Mini for Android <52.2 - CSRF
CVSS 4.7
CVE-2020-22660
HIGH
Ruckus APs and SmartZone Controllers - Secure Boot Bypass via Backup Image Fallback
CVSS 7.5
CVE-2020-19003
MEDIUM
Gate One 1.2.0 - Authentication Bypass via Origin Verification Spoofing
CVSS 5.3
CVE-2020-27970
MEDIUM
Yandex Browser < 20.10.0 - Address Bar Spoofing
CVSS 5.3
CVE-2020-7388
CRITICAL
Sage X3 AdxAdmin < 93.2.53 - Unauthenticated Remote Command Execution via AdxDSrv.exe Authentication Bypass
CVSS 10.0
CVE-2020-13529
MEDIUM
systemd - Denial of Service via DHCP FORCERENEW Packet Spoofing
CVSS 6.1
CVE-2020-36128
HIGH
PAXSTORE < 7.0.8_20200511171508 - Authentication Bypass via X-Terminal-Token Spoofing
CVSS 8.2
Details
Vulnerabilities
637