← Back
CWE-290

627 CVEs • Abstraction: Base

Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

JSON object

Loading...

CVEs (627)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
1Thunderbird
Jun 17, 2026
May 14, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type t...Show more
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.Show less
1Mozilla
1Thunderbird
Jun 17, 2026
May 14, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird...Show more
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats spoofed@example.com as the actual address. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.Show less
1Dell
1Wyse Management Suite
Jun 17, 2026
May 8, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Inf...Show more
Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.Show less
-
-
Jun 17, 2026
May 1, 2025
6.9 MEDIUM· v4
N/A· v3
N/A· v2
Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the...Show more
Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper authorization. This issue has been patched in versions 2.6.7, 2.7.0, and 3.0.0. It is recommended to upgrade to version 3.0.0 or greater.Show less
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Apr 30, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.
1Mytel
1Telecom Online Account System
Jun 17, 2026
Apr 25, 2025
N/A· v4
7.0 HIGH· v3
N/A· v2
An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.
1Dataease
1Dataease
Jun 17, 2026
Apr 23, 2025
8.2 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.
-
-
Jun 17, 2026
Apr 22, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application set...Show more
Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings.Show less
1Octoprint
1Octoprint
Jun 17, 2026
Apr 22, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerability that allows an attacker to bypass the login redirect and directly access the...Show more
OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerability that allows an attacker to bypass the login redirect and directly access the rendered HTML of certain frontend pages. The primary risk lies in potential future modifications to the codebase that might incorrectly rely on the vulnerable internal functions for authentication checks, leading to security vulnerabilities. This issue has been patched in version 1.11.0.Show less
1Honor
1Gamecenter
Jun 17, 2026
Apr 17, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service confidentiality and integrity.
1Jellyfin
1Jellyfin
Jun 17, 2026
Apr 15, 2025
4.6 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Jellyfin is an open source self hosted media server. In versions 10.9.0 to before 10.10.7, the /System/Restart endpoint provides administrators the ability to restart their Jellyfin server. This endpoint is intended to b...Show more
Jellyfin is an open source self hosted media server. In versions 10.9.0 to before 10.10.7, the /System/Restart endpoint provides administrators the ability to restart their Jellyfin server. This endpoint is intended to be admins-only, but it also authorizes requests from any device in the same local network as the Jellyfin server. Due to the method Jellyfin uses to determine the source IP of a request, an unauthenticated attacker is able to spoof their IP to appear as a LAN IP, allowing them to restart the Jellyfin server process without authentication. This means that an unauthenticated attacker could mount a denial-of-service attack on any default-configured Jellyfin server by simply sending the same spoofed request every few seconds to restart the server over and over. This method of IP spoofing also bypasses some security mechanisms, cause a denial-of-service attack, and possible bypass the admin restart requirement if combined with remote code execution. This issue is patched in version 10.10.7.Show less
2Canonical
Gnome
2Control Center
Ubuntu Linux
Jun 17, 2026
Apr 15, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed...Show more
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.Show less
1Ays Pro
1Survey Maker
Jun 17, 2026
Apr 10, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker survey-maker allows Identity Spoofing.This issue affects Survey Maker: from n/a through <= 5.1.6.3.
-
-
Jun 17, 2026
Apr 10, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Authentication Bypass by Spoofing vulnerability in Asgaros Asgaros Forum asgaros-forum allows Identity Spoofing.This issue affects Asgaros Forum: from n/a through <= 3.0.0.
1Totvs
1Framework (linha Protheus)
Jun 17, 2026
Apr 9, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Apr 7, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Apr 7, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Apr 7, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Apr 7, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Apr 7, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.