CWE-290
627 CVEs • Abstraction: Base
Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CVEs (627)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Common is a package of common modules that can be accessed by NIMBLE services. Common before commit number 3b96cb0293d3443b870351945f41d7d55cb34b53 did not properly verify the signature of JSON Web Tokens. This allows so...Show more |
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While exploiting this does requi...Show more |
Windows Hello Security Feature Bypass Vulnerability |
1Schneider Electric 32Ecostruxure Control Expert Ecostruxure Process ExpertModicon M340 Bmxp341000 Firmware+29 moreJun 17, 2026 Jul 14, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Exper...Show more |
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream. |
If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without proper authentication. Roon Labs has already fixed this vulnerability in the following versions: Roon Ser...Show more |
An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is enabled, Kiali assumes that some of the token validation is handled by t...Show more |
Microsoft Exchange Server Spoofing Vulnerability |
Microsoft Exchange Server Remote Code Execution Vulnerability |
1Microsoft 2Sharepoint Foundation Sharepoint ServerJun 17, 2026 May 11, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Microsoft SharePoint Server Spoofing Vulnerability |
1Microsoft 2Sharepoint Foundation Sharepoint ServerJun 17, 2026 May 11, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Microsoft SharePoint Server Spoofing Vulnerability |
1Microsoft 2Sharepoint Foundation Sharepoint ServerJun 17, 2026 May 11, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Microsoft SharePoint Server Spoofing Vulnerability |
3Fedoraproject NetappSystemd Project4Active Iq Unified Manager Cloud BackupFedora+1 moreJun 17, 2026 May 10, 2021 N/A· v4 6.1 MEDIUM· v3 2.9 LOW· v2 An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can...Show more |
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store...Show more |
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the Au...Show more |
1Homeautomation Project 1Homeautomation Jun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart ho...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page. |
2Fedoraproject Juniper2Fedora Paragon Active Assurance Control CenterJun 17, 2026 Apr 22, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and ac...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Apr 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory l...Show more |