This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
637 vulnerabilities with CWE-290
CVE-2025-26421
MEDIUM
Android - Authentication Bypass via Lock Screen Logic Error
CVSS 4.0
CVE-2025-56689
MEDIUM
One Identity Safeguard for Privileged Passwords 7.5.1.20903 - Authentication Bypass via OTP Response Replay
CVSS 4.6
CVE-2025-56608
MEDIUM
Android Corona Virus Tracker App India 1.0 - Authentication Bypass via MD5 Digest Spoofing
CVSS 4.2
CVE-2025-6188
HIGH
Arista EOS 4.30.0-4.33.1.2F - Authentication Bypass via Spoofed UDP Port 3503 Packets
CVSS 7.5
CVE-2025-8853
CRITICAL
Official Document Management System - Auth Bypass
CVSS 9.8
CVE-2025-36119
HIGH
IBM i 7.3-7.6 - Authenticated Privilege Escalation via Web Session Hijacking in Digital Certificate Manager
CVSS 7.1
CVE-2025-50454
MEDIUM
Blue Access Cobalt X1 <02.000.187 - Auth Bypass
CVSS 6.5
CVE-2025-36594
CRITICAL
Dell Data Domain Operating System - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2025-46018
MEDIUM
CSC Pay Mobile App 2.19.4 - Authentication Bypass via Bluetooth Disabling
CVSS 5.4
CVE-2025-54576
CRITICAL
oauth2-proxy < 7.11.0 - Authentication Bypass via Skip Auth Routes Regex Matching
CVSS 9.1
CVE-2025-43245
CRITICAL
macOS <15.6-13.7.7 - Info Disclosure
CVSS 9.8
CVE-2025-31511
HIGH
AlertEnterprise Guardian <4.1.14.2.2.1 - Auth Bypass
CVSS 7.3
CVE-2025-34065
MEDIUM
AVTECH IP camera, DVR, and NVR Devices - Unauthenticated Authentication Bypass via /nobody URL Path
CVE-2025-34063
CRITICAL
OneLogin AD Connector <6.1.5 - Auth Bypass
CVE-2025-34053
MEDIUM
AVTECH IP camera, DVR, and NVR devices - Authentication Bypass via .cab URL Spoofing
CVE-2025-23168
MEDIUM
Versa Director - Authentication Bypass via 2FA OTP Redirection and Reuse
CVSS 6.3
CVE-2025-48937
MEDIUM
matrix-sdk-crypto <0.11.1-0.12.0 - Info Disclosure
CVSS 4.9
CVE-2025-49004
HIGH
Caido < 0.48.0 - Authentication Bypass and Remote Code Execution via DNS Rebinding
CVSS 7.5
CVE-2025-48906
HIGH
HarmonyOS - Authentication Bypass in DSoftBus Module
CVSS 8.8
CVE-2025-49002
CRITICAL
DataEase < 2.10.10 - Authentication Bypass via Case Insensitivity
CVSS 9.8
CVE-2025-5067
MEDIUM
Google Chrome < 137.0.7151.55 - UI Spoofing via Tab Strip
CVSS 5.4
CVE-2025-48027
MEDIUM
MutonUfoAI pGina.Fork < 3.9.9.12 - Authentication Bypass via DNS Spoofing
CVSS 5.4
CVE-2025-3875
HIGH
Thunderbird < 128.10.0, 128.10.1-128.*, >=138.0.1 - Sender Spoofing via Invalid From Header Parsing
CVSS 7.5
CVE-2025-27695
MEDIUM
Dell Wyse Management Suite < 5.1 - Authentication Bypass by Spoofing
CVSS 4.9
CVE-2025-46345
MEDIUM
Auth0 Account Link Extension <2.6.6 - Info Disclosure
Details
Vulnerabilities
637