CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

535 vulnerabilities with CWE-290
CVE-2025-12653 MEDIUM
GitLab CE/EE <18.4.5-18.6.1 - Info Disclosure
CVSS 6.5
CVE-2025-12414 CRITICAL
Looker - Info Disclosure
CVE-2025-13015 LOW
Mozilla Firefox < 115.30.0 - Authentication Bypass by Spoofing
CVSS 3.4
CVE-2025-12430 HIGH
Google Chrome < 142.0.7444.59 - Authentication Bypass by Spoofing
CVSS 7.5
CVE-2025-11209 HIGH
Google Chrome <141.0.7390.54 - XSS
CVSS 8.2
CVE-2025-27916 HIGH
Anydesk < 9.0.4 - Authentication Bypass by Spoofing
CVSS 7.5
CVE-2025-58595 MEDIUM
All In One Login <2.0.9 - Auth Bypass
CVSS 5.3
CVE-2025-43503 MEDIUM
watchOS <26.1 - Info Disclosure
CVSS 4.3
CVE-2025-43493 MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 4.3
CVE-2025-59501 MEDIUM
Microsoft Configuration Manager 2403 < 5.00.9128.1037 - Authentication Bypass by Spoofing
CVSS 4.8
CVE-2025-11843 HIGH
Therefore Corporation GmbH - Privilege Escalation
CVE-2025-5605 MEDIUM
Wso2 API Control Plane - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2025-56800 MEDIUM
Reolink - Authentication Bypass by Spoofing
CVSS 5.1
CVE-2025-37147 HIGH
Access Point - Privilege Escalation
CVSS 7.1
CVE-2025-9265 CRITICAL
Kiloview NDI N30 - Auth Bypass
CVE-2025-60868 MEDIUM
Statamic Alt Redirect 1.6.3 - SSRF
CVSS 6.5
CVE-2025-61778 CRITICAL
Nuget Akka.remote < 1.5.52 - Missing Authentication
CVE-2025-54288 MEDIUM
Canonical Lxd < 5.21.4 - Authentication Bypass by Spoofing
CVSS 6.8
CVE-2025-59956 MEDIUM
AgentAPI <0.3.3 - SSRF
CVSS 6.5
CVE-2025-56449 HIGH
Obsidian Scheduler <6.3.0 - Auth Bypass
CVSS 8.2
CVE-2025-10530 MEDIUM
Mozilla Firefox < 143.0 - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2025-59154 MEDIUM
Org.igniterealtime.openfire Xmppserver < 5.0.2 - Authentication Bypass by Spoofing
CVSS 5.9
CVE-2025-7448 HIGH
Wi-SUN - Info Disclosure
CVE-2025-26419 LOW
Google Android - Authentication Bypass by Spoofing
CVSS 3.3
CVE-2025-26428 LOW
Google Android - Authentication Bypass by Spoofing
CVSS 3.2
Details
Vulnerabilities 535