CWE-290
627 CVEs • Abstraction: Base
Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CVEs (627)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentiality and availability. |
1Strategy11 1Formidable Form Builder Jun 17, 2026 Mar 27, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections. |
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability |
1Microsoft 4365 Apps ExcelOffice+1 moreJun 17, 2026 Mar 14, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Microsoft Excel Spoofing Vulnerability |
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing |
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user h...Show more |
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server uses the request header `x-forwarded-for` to determine the client IP address. If Parse Server doesn't r...Show more |
1Mitsubishielectric 3Gt25 Firmware Gt27 FirmwareGt Softgot2000Jun 17, 2026 Feb 2, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Authentication Bypass by Spoofing vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.14.000 to 01.47.000, Mitsubishi Electric Corporation GOT2000 Series GT25 model versions 01.14.000 t...Show more |
1Schneider Electric 1Ecostruxure Cybersecurity Admin Expert Jun 17, 2026 Jan 30, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected...Show more |
An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address re...Show more |
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin. |
The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based restrictions on login forms. |
1Ruckuswireless 14R310 Firmware R500 FirmwareR600 Firmware+11 moreJun 17, 2026 Jan 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZon...Show more |
1Cisco 4Rv016 Firmware Rv042 FirmwareRv042g Firmware+1 moreJun 17, 2026 Jan 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow an unauthenticated, remote attacker to bypass authentication on an affected device. Thi...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 22, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Fi...Show more |
1Microsoft 2Office Office Long Term Servicing ChannelJun 17, 2026 Dec 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Microsoft Outlook for Mac Spoofing Vulnerability |
1Samsung 15T Ksu2eakuc Firmware T Ksu2edeuc FirmwareT Ksu2euab Firmware+12 moreJun 17, 2026 Dec 13, 2022 N/A· v4 4.6 MEDIUM· v3 N/A· v2 The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E917...Show more |
1Wut 16Com Server ++ Firmware Com Server 20ma FirmwareCom Server Highspeed 100basefx Firmware+13 moreJun 17, 2026 Dec 13, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can...Show more |
1Kyocera 38Ecosys M2535dn Firmware Ecosys M6526cdn FirmwareEcosys M6526cidn Firmware+35 moreJun 17, 2026 Dec 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session info...Show more |