CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

575 vulnerabilities with CWE-290
CVE-2025-59802 HIGH
Foxit PDF Editor and Reader < 2025.2.1 - Signature Spoofing via Optional Content Groups
CVSS 7.5
CVE-2025-13953 CRITICAL
GTT Tax Information System - Auth Bypass
CVE-2025-66508 MEDIUM
1Panel < 2.0.14 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 6.5
CVE-2025-66507 HIGH
1Panel < 2.0.14 - Unauthenticated CAPTCHA Bypass via Client-Controlled Parameter
CVSS 7.5
CVE-2025-14327 HIGH
Firefox < 146.0 and ESR 140.7 - Spoofing in Downloads Panel
CVSS 7.5
CVE-2025-66570 CRITICAL
cpp-httplib <0.27.0 - Info Disclosure
CVSS 10.0
CVE-2025-66270 MEDIUM
KDE Connect <2025-11-28 - Info Disclosure
CVSS 4.7
CVE-2025-27389 MEDIUM
ColorOS 11-15 - Authentication Bypass via Application Installation Source Verification
CVE-2025-54305 HIGH
Thermo Fisher Torrent Suite 5.18.1 - Authentication Bypass via LocalhostAuthMiddleware Spoofing
CVSS 7.8
CVE-2025-13636 MEDIUM
Google Chrome < 143.0.7499.40 - UI Spoofing via Split View Domain Name
CVSS 4.3
CVE-2025-13635 MEDIUM
Google Chrome < 143.0.7499.40 - UI Spoofing via Crafted HTML Page
CVSS 4.4
CVE-2025-13634 MEDIUM
Google Chrome < 143.0.7499.40 - Authentication Bypass via Mark of the Web Spoofing
CVSS 4.4
CVE-2025-59699 MEDIUM
Entrust nShield Connect XC, nShield 5c, and nShield HSMi < 13.6.12 - Privilege Escalation via Legacy GRUB Bootloader
CVSS 6.8
CVE-2025-12653 MEDIUM
GitLab CE/EE <18.4.5-18.6.1 - Info Disclosure
CVSS 6.5
CVE-2025-12414 CRITICAL
Google Cloud Looker Authentication Bypass via Email Address String Normalization
CVE-2025-13015 LOW
Firefox < 115.30.0, 115.30-115.*, <140.5, 140.5-140.*, >=145 - Authentication Bypass by Spoofing
CVSS 3.4
CVE-2025-12430 HIGH
Google Chrome < 142.0.7444.59 - UI Spoofing via Media Object Lifecycle Issue
CVSS 7.5
CVE-2025-11209 HIGH
Google Chrome < 141.0.7390.54 - Omnibox Spoofing via Crafted HTML Page
CVSS 8.2
CVE-2025-27916 HIGH
AnyDesk < 9.0.4 - Authentication Bypass by Spoofing via IP Address Manipulation
CVSS 7.5
CVE-2025-58595 MEDIUM
All In One Login <2.0.9 - Auth Bypass
CVSS 5.3
CVE-2025-43503 MEDIUM
Safari < 26.1 - User Interface Spoofing via Inconsistent State Management
CVSS 4.3
CVE-2025-43493 MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 4.3
CVE-2025-59501 MEDIUM
Microsoft Configuration Manager 2403 < 5.00.9128.1037 - Authentication Bypass by Spoofing
CVSS 4.8
CVE-2025-11843 HIGH
Therefore Corporation GmbH - Privilege Escalation
CVE-2025-5605 MEDIUM
WSO2 API Control Plane - Authentication Bypass via Request URI Manipulation
CVSS 4.3
Details
Vulnerabilities 575