This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
575 vulnerabilities with CWE-290
CVE-2024-13685
MEDIUM
Admin and Site Enhancements WordPress Plugin < 7.6.10 - Authentication Bypass via IP Header Spoofing
CVSS 5.3
CVE-2024-36557
MEDIUM
Forever KidsWatch Call Me KW50 and KW60 - Authentication Bypass via IMEI Spoofing
CVSS 6.6
CVE-2024-55925
HIGH
Xerox Workplace Suite - Auth Bypass
CVSS 7.5
CVE-2024-13061
CRITICAL
Electronic Official Document Management System - Auth Bypass
CVSS 9.8
CVE-2024-12108
CRITICAL
WhatsUp Gold 23.1.0-24.0.1 - Authentication Bypass via Public API
CVSS 9.6
CVE-2024-54450
CRITICAL
Kurmi Provisioning Suite 7.9.0.33 - Info Disclosure
CVSS 9.4
CVE-2024-55470
HIGH
Oqtane Framework 6.0.0 - Authentication Bypass via EntityID Parameter Spoofing
CVSS 7.5
CVE-2024-55232
MEDIUM
PHPGurukul Online Notes Sharing Management System 1.0 - Insecure Direct Object Reference
CVSS 5.4
CVE-2024-54158
LOW
JetBrains YouTrack <2024.3.52635 - Open Redirect
CVSS 3.5
CVE-2024-50380
HIGH
Snap One OVRC cloud < 7.3 - Authentication Bypass via MAC Address Spoofing
CVE-2024-53862
HIGH
Argo Workflows 3.5.7-3.5.12 - Unauthenticated Workflow Archive Access via Spoofed Token
CVSS 7.5
CVE-2024-36466
HIGH
Zabbix 6.0.0-6.0.31 - Authentication Bypass via Forged zbx_session Cookie
CVSS 8.8
CVE-2024-11701
MEDIUM
Firefox < 133 and Thunderbird < 133 - Authentication Bypass by Spoofing via Address Bar Display
CVSS 4.3
CVE-2024-11692
MEDIUM
Firefox < 133 and ESR < 128.5 - Authentication Bypass by Spoofing via Select Dropdown Overlay
CVSS 4.3
CVE-2024-8935
HIGH
Schneider Electric Modicon M340 CPU, MC80, Momentum Unity M1E - Authentication Bypass via Man-In-The-Middle Attack
CVSS 7.5
CVE-2024-51504
CRITICAL
Apache ZooKeeper 3.9.0-3.9.2 - Authentication Bypass by Spoofing via X-Forwarded-For Header
CVSS 9.1
CVE-2024-51406
MEDIUM
Floodlight SDN Open Flow Controller 1.2 - Authentication Bypass by Spoofing via Fake LLDP Packets
CVSS 6.2
CVE-2024-10465
MEDIUM
Firefox < 132 and ESR < 128.4 - Authentication Bypass by Spoofing via Persistent Clipboard Paste Button
CVSS 6.5
CVE-2024-10462
MEDIUM
Firefox < 132 and ESR < 128.4 - Origin Spoofing via Truncated URL in Permission Prompt
CVSS 6.5
CVE-2024-20384
MEDIUM
Cisco ASA Software - Unauthenticated Access Control Bypass via ACL Logic Error
CVSS 5.8
CVE-2024-20299
MEDIUM
Cisco ASA Software Unauthenticated ACL Bypass via AnyConnect
CVSS 5.8
CVE-2024-20297
MEDIUM
Cisco Adaptive Security Appliance Software - Unauthenticated Access Control List Bypass via AnyConnect Session
CVSS 5.8
CVE-2024-8901
HIGH
AWS ALB Route Directive Adapter For Istio - Auth Bypass
CVSS 7.5
CVE-2024-10125
HIGH
Amazon.ApplicationLoadBalancer.Identity.AspNetCore - Info Disclosure
CVSS 7.5
CVE-2024-49214
MEDIUM
HAProxy <3.1-dev7, <3.0.5, <2.9.11 - SSRF
CVSS 5.3
Details
Vulnerabilities
575