CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

535 vulnerabilities with CWE-290
CVE-2025-26421 MEDIUM
Google Android - Authentication Bypass by Spoofing
CVSS 4.0
CVE-2025-56689 MEDIUM
Quest One Identity - Authentication Bypass by Spoofing
CVSS 4.6
CVE-2025-56608 MEDIUM
Donbermoy Android Corona Virus Tracke... - Authentication Bypass by Spoofing
CVSS 4.2
CVE-2025-6188 HIGH
Arista EOS - DoS
CVSS 7.5
CVE-2025-8853 CRITICAL
Official Document Management System - Auth Bypass
CVSS 9.8
CVE-2025-36119 HIGH
I - Authentication Bypass by Spoofing
CVSS 7.1
CVE-2025-50454 MEDIUM
Blue Access Cobalt X1 <02.000.187 - Auth Bypass
CVSS 6.5
CVE-2025-36594 CRITICAL
Dell Data Domain Operating System - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2025-46018 MEDIUM
Cscsw Pay Mobile - Authentication Bypass by Spoofing
CVSS 5.4
CVE-2025-54576 CRITICAL
Oauth2 Proxy < 7.11.0 - Authentication Bypass by Spoofing
CVSS 9.1
CVE-2025-43245 CRITICAL
macOS <15.6-13.7.7 - Info Disclosure
CVSS 9.8
CVE-2025-31511 HIGH
AlertEnterprise Guardian <4.1.14.2.2.1 - Auth Bypass
CVSS 7.3
CVE-2025-34065 MEDIUM
AVTECH - Auth Bypass
CVE-2025-34063 CRITICAL
OneLogin AD Connector <6.1.5 - Auth Bypass
CVE-2025-34053 MEDIUM
AVTECH - Auth Bypass
CVE-2025-23168 MEDIUM
Versa-networks Versa Director - Authentication Bypass by Spoofing
CVSS 6.3
CVE-2025-48937 MEDIUM
matrix-sdk-crypto <0.11.1-0.12.0 - Info Disclosure
CVSS 4.9
CVE-2025-49004 HIGH
Caido <0.48.0 - Code Execution
CVSS 7.5
CVE-2025-48906 HIGH
DSoftBus - Auth Bypass
CVSS 8.8
CVE-2025-49002 CRITICAL
Dataease < 2.10.10 - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2025-5067 MEDIUM
Google Chrome <137.0.7151.55 - XSS
CVSS 5.4
CVE-2025-48027 MEDIUM
pGina.Fork <3.9.9.12 - Auth Bypass
CVSS 5.4
CVE-2025-3875 HIGH
Mozilla Thunderbird < 128.10.0 - Authentication Bypass by Spoofing
CVSS 7.5
CVE-2025-27695 MEDIUM
Dell Wyse Management Suite < 5.1 - Authentication Bypass by Spoofing
CVSS 4.9
CVE-2025-46345 MEDIUM
Auth0 Account Link Extension <2.6.6 - Info Disclosure
Details
Vulnerabilities 535