This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
636 vulnerabilities with CWE-290
CVE-2025-13455
HIGH
ThinkPlus configuration software - Auth Bypass
CVSS 7.8
CVE-2025-11250
CRITICAL
Zohocorp ManageEngine ADSelfService Plus <6519 - Auth Bypass
CVSS 9.1
CVE-2025-62235
HIGH
Apache NimBLE <= 1.8.0 - Authentication Bypass by Spoofing via Security Request
CVSS 8.1
CVE-2025-60538
MEDIUM
shiori < 1.7.4 - Authentication Bypass via Login Page Brute Force
CVSS 6.5
CVE-2025-69258
CRITICAL
Trend Micro Apex Central - Unauthenticated Remote Code Execution via LoadLibraryEX DLL Hijacking
CVSS 9.8
CVE-2025-69203
MEDIUM
Signal K Server < 2.19.0 - Authentication Bypass via X-Forwarded-For Spoofing
CVSS 6.3
CVE-2025-68644
HIGH
Yealink RPS <2025-06-27 - Info Disclosure
CVSS 7.4
CVE-2025-65046
LOW
Microsoft Edge Chromium < 143.0.3650.88 - Spoofing
CVSS 3.1
CVE-2025-59385
CRITICAL
QNAP QTS and QuTS hero - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2025-36754
CRITICAL
Growatt ShineLan-X 3.6.0.0-3.6.0.1 - Unauthenticated Authentication Bypass via Crafted POST Request
CVE-2025-36753
CRITICAL
Growatt ShineLan-X Firmware 3.6.0.0-3.6.0.1 - Unauthenticated Debug Interface Access via SWD
CVSS 9.8
CVE-2025-59802
HIGH
Foxit PDF Editor and Reader < 2025.2.1 - Signature Spoofing via Optional Content Groups
CVSS 7.5
CVE-2025-13953
CRITICAL
GTT Tax Information System - Auth Bypass
CVE-2025-66508
MEDIUM
1Panel < 2.0.14 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 6.5
CVE-2025-66507
HIGH
1Panel < 2.0.14 - Unauthenticated CAPTCHA Bypass via Client-Controlled Parameter
CVSS 7.5
CVE-2025-14327
HIGH
Firefox < 146.0 and ESR 140.7 - Spoofing in Downloads Panel
CVSS 7.5
CVE-2025-66570
CRITICAL
cpp-httplib <0.27.0 - Info Disclosure
CVSS 10.0
CVE-2025-66270
MEDIUM
KDE Connect <2025-11-28 - Info Disclosure
CVSS 4.7
CVE-2025-27389
MEDIUM
ColorOS 11-15 - Authentication Bypass via Application Installation Source Verification
CVE-2025-54305
HIGH
Thermo Fisher Torrent Suite 5.18.1 - Authentication Bypass via LocalhostAuthMiddleware Spoofing
CVSS 7.8
CVE-2025-13636
MEDIUM
Google Chrome < 143.0.7499.40 - UI Spoofing via Split View Domain Name
CVSS 4.3
CVE-2025-13635
MEDIUM
Google Chrome < 143.0.7499.40 - UI Spoofing via Crafted HTML Page
CVSS 4.4
CVE-2025-13634
MEDIUM
Google Chrome < 143.0.7499.40 - Authentication Bypass via Mark of the Web Spoofing
CVSS 4.4
CVE-2025-59699
MEDIUM
Entrust nShield Connect XC, nShield 5c, and nShield HSMi < 13.6.12 - Privilege Escalation via Legacy GRUB Bootloader
CVSS 6.8
CVE-2025-12653
MEDIUM
GitLab CE/EE <18.4.5-18.6.1 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities
636