CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

535 vulnerabilities with CWE-290
CVE-2024-11692 MEDIUM
Firefox < 133 - CSRF
CVSS 4.3
CVE-2024-8935 HIGH
Diffie Hellman - Auth Bypass
CVSS 7.5
CVE-2024-51504 CRITICAL
Apache Zookeeper < 3.9.3 - Authentication Bypass by Spoofing
CVSS 9.1
CVE-2024-51406 MEDIUM
Projectfloodlight Open Sdn Controller - Authentication Bypass by Sp...
CVSS 6.2
CVE-2024-10465 MEDIUM
Mozilla Firefox < 128.4.0 - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2024-10462 MEDIUM
Mozilla Firefox < 128.4.0 - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2024-20384 MEDIUM
Cisco ASA/FTD - Auth Bypass
CVSS 5.8
CVE-2024-20299 MEDIUM
Cisco ASA/FTD - Auth Bypass
CVSS 5.8
CVE-2024-20297 MEDIUM
Cisco ASA/FTD - Auth Bypass
CVSS 5.8
CVE-2024-8901 HIGH
AWS ALB Route Directive Adapter For Istio - Auth Bypass
CVSS 7.5
CVE-2024-10125 HIGH
Amazon.ApplicationLoadBalancer.Identity.AspNetCore - Info Disclosure
CVSS 7.5
CVE-2024-49214 MEDIUM
HAProxy <3.1-dev7, <3.0.5, <2.9.11 - SSRF
CVSS 5.3
CVE-2024-49193 HIGH
Zendesk <2024-07-02 - Info Disclosure
CVSS 7.5
CVE-2024-45397 MEDIUM
h2o - SSRF
CVSS 5.9
CVE-2024-9391 MEDIUM
Mozilla Firefox < 131.0 - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2024-46957 CRITICAL
Mellium.im Xmpp < 0.22.0 - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2024-39341 MEDIUM
Entrust Instant Financial Issuance (On Premise) Software - Info Dis...
CVSS 5.9
CVE-2024-45453 LOW
Peter Hardy-vanDoorn Maintenance Redirect <2.0.1 - Auth Bypass
CVSS 3.7
CVE-2024-8908 MEDIUM
Google Chrome < 129.0.6668.58 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2024-6678 CRITICAL
GitLab CE/EE <17.1.7-17.3.2 - Privilege Escalation
CVSS 9.9
CVE-2024-44104 HIGH
Ivanti Workspace Control - Authentication Bypass by Spoofing
CVSS 8.8
CVE-2024-8399 MEDIUM
Focus for iOS < 130 - XSS
CVSS 4.7
CVE-2024-8386 MEDIUM
Firefox < 130- Thunderbird < 128.2 - XSS
CVSS 6.1
CVE-2024-43944 LOW
Yassine Idrissi Maintenance & Coming Soon Redirect Animation <2.1.3...
CVSS 3.7
CVE-2024-7745 MEDIUM
WS_FTP Server <8.8.8 - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities 535