This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
535 vulnerabilities with CWE-290
CVE-2024-42364
MEDIUM
Homepage 0.9.1 - SSRF
CVSS 6.5
CVE-2024-38807
MEDIUM
Org.springframework.boot Spring-boot-... - Authentication Bypass by Spoofing
CVSS 6.3
CVE-2024-7981
MEDIUM
Google Chrome <128.0.6613.84 - XSS
CVSS 4.3
CVE-2024-35539
MEDIUM
Typecho - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2024-35538
MEDIUM
Typecho - HTTP Request Smuggling
CVSS 5.3
CVE-2024-41432
MEDIUM
Likeshop < 2.5.7.20210811 - Authentication Bypass by Spoofing
CVSS 5.3
CVE-2024-27853
MEDIUM
macOS Sonoma <14.4 - Info Disclosure
CVSS 4.4
CVE-2024-41107
HIGH
Apache Cloudstack < 4.18.2.2 - Authentication Bypass by Spoofing
CVSS 8.1
CVE-2024-37430
MEDIUM
Patreon WordPress <1.9.0 - Auth Bypass
CVSS 5.3
CVE-2024-6163
MEDIUM
Checkmk <2.3.0p10-2.0.0p39 - Auth Bypass
CVSS 5.3
CVE-2024-37082
CRITICAL
Cloud Foundry - Auth Bypass
CVSS 9.1
CVE-2024-39350
HIGH
Synology Bc500 Firmware - Authentication Bypass by Spoofing
CVSS 7.5
CVE-2024-31802
MEDIUM
DESIGNA ABACUS <18 - Auth Bypass
CVSS 6.3
CVE-2024-4846
MEDIUM
Devolutions Server < 2024.1.15.0 - Authentication Bypass by Spoofing
CVSS 6.3
CVE-2024-39337
MEDIUM
Click Studios Passwordstate Core <9.8.9858 - Auth Bypass
CVSS 6.5
CVE-2024-21518
HIGH
Opencart - Path Traversal
CVSS 7.2
CVE-2024-30058
MEDIUM
Microsoft Edge < - SSRF
CVSS 5.4
CVE-2024-36588
MEDIUM
Annonshop.app - Info Disclosure
CVSS 6.5
CVE-2024-5812
LOW
Beyondtrust Beyondinsight Password Safe < 23.2.0.1293 - Authentication Bypass by Spoofing
CVSS 3.3
CVE-2024-35749
LOW
Acurax Under Construction / Maintenan... - Authentication Bypass by Spoofing
CVSS 3.7
CVE-2024-5037
HIGH
Redhat Openshift Container Platform - Authentication Bypass by Spoo...
CVSS 7.5
CVE-2024-4358
CRITICAL
KEV
Telerik Report Server Auth Bypass and Deserialization RCE
CVSS 9.8
CVE-2024-20363
MEDIUM
Cisco Snort IPS - Auth Bypass
CVSS 5.8
CVE-2024-32827
MEDIUM
RafflePress Giveaways and Contests <1.12.7 - Auth Bypass
CVSS 5.3
CVE-2024-32786
MEDIUM
Royal-elementor-addons Royal Elemento... - Authentication Bypass by Spoofing
CVSS 5.3
Details
Vulnerabilities
535