This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
637 vulnerabilities with CWE-290
CVE-2019-16378
CRITICAL
OpenDMARC <1.3.2, <1.4.0-Beta1 - Signature Bypass
CVSS 9.8
CVE-2019-3884
MEDIUM
OpenShift 3.6-3.11, 4.1 - Authentication Bypass via UUID Spoofing
CVSS 5.4
CVE-2019-0283
HIGH
SAP NetWeaver Process Integration - Digital Signature Spoofing via PI Axis Adapter
CVSS 7.1
CVE-2019-10875
MEDIUM
Mi Browser and Mint Browser - URL Spoofing via Query Parameter Handling
CVSS 6.5
CVE-2019-3775
HIGH
Cloud Foundry UAA < 70.0 - Authenticated User Impersonation via Email Address Spoofing
CVSS 7.1
CVE-2018-25361
MEDIUM
Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection
CVSS 6.8
CVE-2018-25318
CRITICAL
Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change
CVSS 9.8
CVE-2018-25317
CRITICAL
Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change
CVSS 9.8
CVE-2018-25316
CRITICAL
Tenda W308R v2 V5.07.48 Cookie Session Weakness DNS Change
CVSS 9.8
CVE-2018-5354
HIGH
ANIXIS Password Reset Client <3.22 - RCE
CVSS 8.8
CVE-2018-5353
CRITICAL
Zoho ManageEngine ADSelfService Plus <5.5.5517 - Privilege Escalation
CVSS 9.8
CVE-2018-7842
CRITICAL
Modicon M580, M340, Quantum, and Premium Firmware - Authentication Bypass via Modbus Parameter Brute Force
CVSS 9.8
CVE-2018-15588
HIGH
MailMate < 1.11.3 - Authentication Bypass via Spoofed HTML/MIME Structure
CVSS 7.5
CVE-2018-16483
HIGH
express-cart <=1.1.5 - Unauthenticated Privilege Escalation via User Addition
CVSS 8.8
CVE-2018-15715
CRITICAL
Zoom < 4.1.34814.1119 (Windows), < 4.1.34801.1116 (Mac), <= 2.4.129780.0915 (Linux) - Unauthenticated Message Spoofing
CVSS 9.8
CVE-2018-3829
MEDIUM
Elastic Cloud Enterprise < 1.1.4 - Authentication Bypass via Invalid Roles Token
CVSS 5.3
CVE-2018-8425
MEDIUM
Microsoft Edge - Spoofing via HTML Content Handling
CVSS 4.3
CVE-2018-1695
HIGH
IBM WebSphere App Server <8.5.5 - CSRF
CVSS 7.3
CVE-2018-8388
MEDIUM
Microsoft Edge - Spoofing via Improper HTML Content Handling
CVSS 4.3
CVE-2018-8383
MEDIUM
Microsoft Edge - Spoofing via HTTP Content Parsing
CVSS 4.3
CVE-2018-8278
MEDIUM
Microsoft Edge - Spoofing via HTML Content Handling
CVSS 6.1
CVE-2018-12331
HIGH
ECOS System Management Appliance <5.2.68 - Auth Bypass
CVSS 7.4
CVE-2018-7160
HIGH
Node.js 6.0.0-6.8.0 and 6.9.0-6.13.1 - Remote Code Execution via DNS Rebinding Attack
CVSS 8.8
CVE-2018-8153
MEDIUM
Microsoft Exchange Server - Spoofing via Outlook Web Access Request Handling
CVSS 5.4
CVE-2017-12095
MEDIUM
Circle with Disney Firmware 2.0.1 - Authentication Bypass via Spoofed De-Auth Packets
CVSS 6.5
Details
Vulnerabilities
637