← Back
CWE-290

690 CVEs • Abstraction: Base

Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

JSON object

Loading...

CVEs (690)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Feb 18, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Authentication bypass by spoofing issue exists in FileMegane versions above 1.0.0.0 prior to 3.4.0.0, which may lead to user impersonation. If exploited, restricted file contents may be accessed.
-
-
Jun 17, 2026
Feb 14, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.
-
-
Jun 17, 2026
Feb 12, 2025
N/A· v4
9.4 CRITICAL· v3
N/A· v2
Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a S...Show more
Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with ALB and installed in a way that the application is accessible not through the ALB itself. This vulnerability may also allow for server-side request forgery which may lead to code execution or further privileges escalations when using the AWS metadata URL. This scenario assumes that Stroom must be configured to use ALB Authentication integration and the application is network accessible. The vulnerability has been fixed in versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2.Show less
1Wpgateway
1Wpgateway
Jun 17, 2026
Feb 11, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.
1Dlink
1Dhp W310av Firmware
Jun 17, 2026
Feb 7, 2025
6.9 MEDIUM· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by spoofing. The attack can be initiated remot...Show more
A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by spoofing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
-
-
Jun 17, 2026
Feb 6, 2025
N/A· v4
6.6 MEDIUM· v3
N/A· v2
The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious use...Show more
The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.Show less
1Microsoft
1Azure Ai Face Service
Jun 17, 2026
Jan 29, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.
-
-
Jun 17, 2026
Jan 27, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Authentication Bypass by Spoofing vulnerability in bestwebsoft Google Captcha google-captcha allows Identity Spoofing.This issue affects Google Captcha: from n/a through <= 1.78.
1Xerox
1Workplace Suite
Jun 17, 2026
Jan 23, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an att...Show more
In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This exploit targets improper host validation, potentially exposing sensitive API endpoints.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Jan 21, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
1Google
1Chrome
Jun 17, 2026
Jan 15, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium...Show more
Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Chrome
Jun 17, 2026
Jan 15, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
-
-
Jun 17, 2026
Dec 31, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated rem...Show more
The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.Show less
1Progress
1Whatsup Gold
Jun 17, 2026
Dec 31, 2024
N/A· v4
9.6 CRITICAL· v3
N/A· v2
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
-
-
Jun 17, 2026
Dec 27, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header ra...Show more
An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header rather than the real IP address that the user logged in from. This fake IP address can later be displayed in the My Account popup that shows the IP address that was used to log in.Show less
-
-
Jun 17, 2026
Dec 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data witho...Show more
Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the issue, as the application relies on client-side information for authentication.Show less
1Phpgurukul
1Online Notes Sharing Management System
Jun 17, 2026
Dec 18, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. Th...Show more
An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.Show less
-
-
Jun 17, 2026
Dec 13, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows Functionality Bypass.This issue affects Secure Admin IP: from n/a through 2.0.
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
-
-
Jun 17, 2026
Dec 2, 2024
8.7 HIGH· v4
N/A· v3
N/A· v2
Snap One OVRC cloud uses the MAC address as an identifier to provide information when requested. An attacker can impersonate other devices by supplying enumerated MAC addresses and receive sensitive information about the...Show more
Snap One OVRC cloud uses the MAC address as an identifier to provide information when requested. An attacker can impersonate other devices by supplying enumerated MAC addresses and receive sensitive information about the device.Show less