CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

535 vulnerabilities with CWE-290
CVE-2025-69401 HIGH
WooODT Lite <=2.5.2 - Auth Bypass
CVSS 7.5
CVE-2025-13455 HIGH
ThinkPlus configuration software - Auth Bypass
CVSS 7.8
CVE-2025-11250 CRITICAL
Zohocorp ManageEngine ADSelfService Plus <6519 - Auth Bypass
CVSS 9.1
CVE-2025-62235 HIGH
Apache Nimble < 1.9.0 - Authentication Bypass by Spoofing
CVSS 8.1
CVE-2025-60538 MEDIUM
shiori <1.7.4 - Auth Bypass
CVSS 6.5
CVE-2025-69258 CRITICAL
Trendmicro Apex Central - Origin Validation Error
CVSS 9.8
CVE-2025-69203 MEDIUM
Signalk Signal K Server < 2.19.0 - Authentication Bypass by Spoofing
CVSS 6.3
CVE-2025-68644 HIGH
Yealink RPS <2025-06-27 - Info Disclosure
CVSS 7.4
CVE-2025-65046 LOW
Microsoft Edge Chromium - Authentication Bypass by Spoofing
CVSS 3.1
CVE-2025-59385 CRITICAL
Qnap Qts - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2025-36754 CRITICAL
Web Interface - Auth Bypass
CVE-2025-36753 CRITICAL
Growatt Shine Lan-x Firmware - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2025-59802 HIGH
Foxit Pdf Editor < 13.2.0.63256 - Authentication Bypass by Spoofing
CVSS 7.5
CVE-2025-13953 CRITICAL
GTT Tax Information System - Auth Bypass
CVE-2025-66508 MEDIUM
1Panel <2.0.14 - SSRF
CVSS 6.5
CVE-2025-66507 HIGH
1Panel <2.0.13 - Auth Bypass
CVSS 7.5
CVE-2025-14327 HIGH
Firefox < 146 - SSRF
CVSS 7.5
CVE-2025-66570 CRITICAL
cpp-httplib <0.27.0 - Info Disclosure
CVSS 10.0
CVE-2025-66270 MEDIUM
KDE Connect <2025-11-28 - Info Disclosure
CVSS 4.7
CVE-2025-27389 MEDIUM
ColorOS - Info Disclosure
CVE-2025-54305 HIGH
Thermofisher Torrent Suite Software - Authentication Bypass by Spoo...
CVSS 7.8
CVE-2025-13636 MEDIUM
Google Chrome < 143.0.7499.40 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2025-13635 MEDIUM
Google Chrome < 143.0.7499.40 - Authentication Bypass by Spoofing
CVSS 4.4
CVE-2025-13634 MEDIUM
Google Chrome < 143.0.7499.40 - Authentication Bypass by Spoofing
CVSS 4.4
CVE-2025-59699 MEDIUM
Entrust Nshield 5C Firmware - Authentication Bypass by Spoofing
CVSS 6.8
Details
Vulnerabilities 535