This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
637 vulnerabilities with CWE-290
CVE-2025-12653
MEDIUM
GitLab CE/EE <18.4.5-18.6.1 - Info Disclosure
CVSS 6.5
CVE-2025-12414
CRITICAL
Google Cloud Looker Authentication Bypass via Email Address String Normalization
CVE-2025-13015
LOW
Firefox < 115.30.0, 115.30-115.*, <140.5, 140.5-140.*, >=145 - Authentication Bypass by Spoofing
CVSS 3.4
CVE-2025-12430
HIGH
Google Chrome < 142.0.7444.59 - UI Spoofing via Media Object Lifecycle Issue
CVSS 7.5
CVE-2025-11209
HIGH
Google Chrome < 141.0.7390.54 - Omnibox Spoofing via Crafted HTML Page
CVSS 8.2
CVE-2025-27916
HIGH
AnyDesk < 9.0.4 - Authentication Bypass by Spoofing via IP Address Manipulation
CVSS 7.5
CVE-2025-58595
MEDIUM
All In One Login <2.0.9 - Auth Bypass
CVSS 5.3
CVE-2025-43503
MEDIUM
Safari < 26.1 - User Interface Spoofing via Inconsistent State Management
CVSS 4.3
CVE-2025-43493
MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 4.3
CVE-2025-59501
MEDIUM
Microsoft Configuration Manager 2403 < 5.00.9128.1037 - Authentication Bypass by Spoofing
CVSS 4.8
CVE-2025-11843
HIGH
Therefore Corporation GmbH - Privilege Escalation
CVE-2025-5605
MEDIUM
WSO2 API Control Plane - Authentication Bypass via Request URI Manipulation
CVSS 4.3
CVE-2025-56800
MEDIUM
Reolink 8.18.12 - Authentication Bypass via Client-Side Lock Screen Password Property
CVSS 5.1
CVE-2025-37147
HIGH
Access Point - Privilege Escalation
CVSS 7.1
CVE-2025-9265
CRITICAL
Kiloview NDI N30 < 2.02.246 - Unauthenticated Broken Authorization
CVE-2025-60868
MEDIUM
Alt Redirect < 1.6.4 - Authentication Bypass via Query String Parameter Spoofing
CVSS 6.5
CVE-2025-61778
CRITICAL
Akka.Remote 1.2.0-1.5.51 - Authentication Bypass via Missing Mutual TLS Enforcement
CVE-2025-54288
MEDIUM
Canonical LXD 4.0-5.21.4 - Authenticated Information Spoofing via Process Name
CVSS 6.8
CVE-2025-59956
MEDIUM
coder/agentapi < 0.4.0 - Unauthorized Data Exfiltration via DNS Rebinding Attack
CVSS 6.5
CVE-2025-56449
HIGH
Obsidian Scheduler <6.3.0 - Auth Bypass
CVSS 8.2
CVE-2025-10530
MEDIUM
Firefox for Android < 143.0 - Authentication Bypass by Spoofing in WebAuthn Component
CVSS 6.5
CVE-2025-59154
MEDIUM
Org.igniterealtime.openfire Xmppserver < 5.0.2 - Authentication Bypass by Spoofing
CVSS 5.9
CVE-2025-7448
HIGH
Wi-SUN Stack >=2.6.0 <2.6.0 - Authentication Bypass by Spoofing via 4-Way Handshake
CVE-2025-26419
LOW
Android - Authentication Bypass via SystemSettingsFragment Logic Error
CVSS 3.3
CVE-2025-26428
LOW
Android - Lock Screen Bypass via LockTaskController Logic Error
CVSS 3.2
Details
Vulnerabilities
637