CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2025-12653 MEDIUM
GitLab CE/EE <18.4.5-18.6.1 - Info Disclosure
CVSS 6.5
CVE-2025-12414 CRITICAL
Google Cloud Looker Authentication Bypass via Email Address String Normalization
CVE-2025-13015 LOW
Firefox < 115.30.0, 115.30-115.*, <140.5, 140.5-140.*, >=145 - Authentication Bypass by Spoofing
CVSS 3.4
CVE-2025-12430 HIGH
Google Chrome < 142.0.7444.59 - UI Spoofing via Media Object Lifecycle Issue
CVSS 7.5
CVE-2025-11209 HIGH
Google Chrome < 141.0.7390.54 - Omnibox Spoofing via Crafted HTML Page
CVSS 8.2
CVE-2025-27916 HIGH
AnyDesk < 9.0.4 - Authentication Bypass by Spoofing via IP Address Manipulation
CVSS 7.5
CVE-2025-58595 MEDIUM
All In One Login <2.0.9 - Auth Bypass
CVSS 5.3
CVE-2025-43503 MEDIUM
Safari < 26.1 - User Interface Spoofing via Inconsistent State Management
CVSS 4.3
CVE-2025-43493 MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 4.3
CVE-2025-59501 MEDIUM
Microsoft Configuration Manager 2403 < 5.00.9128.1037 - Authentication Bypass by Spoofing
CVSS 4.8
CVE-2025-11843 HIGH
Therefore Corporation GmbH - Privilege Escalation
CVE-2025-5605 MEDIUM
WSO2 API Control Plane - Authentication Bypass via Request URI Manipulation
CVSS 4.3
CVE-2025-56800 MEDIUM
Reolink 8.18.12 - Authentication Bypass via Client-Side Lock Screen Password Property
CVSS 5.1
CVE-2025-37147 HIGH
Access Point - Privilege Escalation
CVSS 7.1
CVE-2025-9265 CRITICAL
Kiloview NDI N30 < 2.02.246 - Unauthenticated Broken Authorization
CVE-2025-60868 MEDIUM
Alt Redirect < 1.6.4 - Authentication Bypass via Query String Parameter Spoofing
CVSS 6.5
CVE-2025-61778 CRITICAL
Akka.Remote 1.2.0-1.5.51 - Authentication Bypass via Missing Mutual TLS Enforcement
CVE-2025-54288 MEDIUM
Canonical LXD 4.0-5.21.4 - Authenticated Information Spoofing via Process Name
CVSS 6.8
CVE-2025-59956 MEDIUM
coder/agentapi < 0.4.0 - Unauthorized Data Exfiltration via DNS Rebinding Attack
CVSS 6.5
CVE-2025-56449 HIGH
Obsidian Scheduler <6.3.0 - Auth Bypass
CVSS 8.2
CVE-2025-10530 MEDIUM
Firefox for Android < 143.0 - Authentication Bypass by Spoofing in WebAuthn Component
CVSS 6.5
CVE-2025-59154 MEDIUM
Org.igniterealtime.openfire Xmppserver < 5.0.2 - Authentication Bypass by Spoofing
CVSS 5.9
CVE-2025-7448 HIGH
Wi-SUN Stack >=2.6.0 <2.6.0 - Authentication Bypass by Spoofing via 4-Way Handshake
CVE-2025-26419 LOW
Android - Authentication Bypass via SystemSettingsFragment Logic Error
CVSS 3.3
CVE-2025-26428 LOW
Android - Lock Screen Bypass via LockTaskController Logic Error
CVSS 3.2
Details
Vulnerabilities 637