CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

575 vulnerabilities with CWE-290
CVE-2026-24853 HIGH
caido < 0.55.0 - Authentication Bypass via X-Forwarded-Host Header Spoofing
CVSS 8.1
CVE-2026-25938 CRITICAL
FUXA 1.2.8-1.2.10 - Unauthenticated Remote Code Execution via Node-RED Plugin
CVSS 9.8
CVE-2026-21862 HIGH
rustfs < 1.0.0-alpha.78 - Authentication Bypass via Spoofed X-Forwarded-For Header
CVSS 7.5
CVE-2026-0834 HIGH
TP-Link Archer C20 v5/v6, AX53 v1, TL-WR841N v13 - Unauthenticated RCE via TDDP
CVSS 8.8
CVE-2026-22797 CRITICAL
OpenStack keystonemiddleware <10.7.2, 10.8, 10.9 before 10.9.1, 10....
CVSS 9.9
CVE-2026-0890 MEDIUM
Firefox < 147.0 and Thunderbird < 147.0 - Authentication Bypass by Spoofing via DOM Copy & Paste and Drag & Drop
CVSS 5.4
CVE-2026-21894 MEDIUM
n8n 0.150.0-2.2.1 - Unauthenticated Workflow Trigger via Stripe Webhook Spoofing
CVSS 6.5
CVE-2025-50328 HIGH
B1 Free Archiver 1.5.86 - Auth Bypass
CVSS 7.3
CVE-2025-59707 CRITICAL
N2W <4.3.2 - Spoofing-Based Code Execution and Credential Theft
CVSS 9.8
CVE-2025-59706 CRITICAL
N2W <4.3.2 and 4.4.0 - API Parameter Remote Code Execution
CVSS 9.8
CVE-2025-67298 HIGH
ClasroomIO <0.2.6 - Privilege Escalation
CVSS 8.1
CVE-2025-48840 MEDIUM
Fortinet FortiWeb 7.0-7.6.3 - Auth Bypass
CVSS 5.3
CVE-2025-71056 HIGH
GCOM EPON 1GE ONU C00R371V00B01 - Auth Bypass
CVSS 8.1
CVE-2025-69401 HIGH
WooODT Lite <= 2.5.2 - Authentication Bypass by Spoofing
CVSS 7.5
CVE-2025-13455 HIGH
ThinkPlus configuration software - Auth Bypass
CVSS 7.8
CVE-2025-11250 CRITICAL
Zohocorp ManageEngine ADSelfService Plus <6519 - Auth Bypass
CVSS 9.1
CVE-2025-62235 HIGH
Apache NimBLE <= 1.8.0 - Authentication Bypass by Spoofing via Security Request
CVSS 8.1
CVE-2025-60538 MEDIUM
shiori < 1.7.4 - Authentication Bypass via Login Page Brute Force
CVSS 6.5
CVE-2025-69258 CRITICAL
Trend Micro Apex Central - Unauthenticated Remote Code Execution via LoadLibraryEX DLL Hijacking
CVSS 9.8
CVE-2025-69203 MEDIUM
Signal K Server < 2.19.0 - Authentication Bypass via X-Forwarded-For Spoofing
CVSS 6.3
CVE-2025-68644 HIGH
Yealink RPS <2025-06-27 - Info Disclosure
CVSS 7.4
CVE-2025-65046 LOW
Microsoft Edge Chromium < 143.0.3650.88 - Spoofing
CVSS 3.1
CVE-2025-59385 CRITICAL
QNAP QTS and QuTS hero - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2025-36754 CRITICAL
Growatt ShineLan-X 3.6.0.0-3.6.0.1 - Unauthenticated Authentication Bypass via Crafted POST Request
CVE-2025-36753 CRITICAL
Growatt ShineLan-X Firmware 3.6.0.0-3.6.0.1 - Unauthenticated Debug Interface Access via SWD
CVSS 9.8
Details
Vulnerabilities 575