CWE-290
690 CVEs • Abstraction: Base
Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CVEs (690)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page. |
2Fedoraproject Juniper2Fedora Paragon Active Assurance Control CenterJun 17, 2026 Apr 22, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and ac...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Apr 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory l...Show more |
8Broadcom DebianFedoraproject+5 more11Communications Billing And Revenue Management Debian LinuxEssbase+8 moreJun 17, 2026 Apr 1, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confus...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Mar 31, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof...Show more |
An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipulated client-side) is used for the internal application logs, an attacker can inject wrong IP addresse...Show more |
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database adapter...Show more |
2Google Microsoft2Chrome Edge ChromiumJun 17, 2026 Feb 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page. |
Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A mi...Show more |
4Arista DebianFedoraproject+1 more4Debian Linux DnsmasqEos+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries c...Show more |
1Sooil 3Anydana A Firmware Anydana I FirmwareDiabecare Rs FirmwareJun 17, 2026 Jan 19, 2021 N/A· v4 5.7 MEDIUM· v3 2.9 LOW· v2 SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures to authenticate the communicating entiti...Show more |
1Microsoft 1Azure Kubernetes Service Jun 17, 2026 Jan 12, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Azure Active Directory Pod Identity Spoofing Vulnerability |
Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can res...Show more |
1Openasset 1Digital Asset Management Jul 9, 2026 Dec 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost...Show more |
1Omniauth Apple Project 1Omniauth Apple Jun 17, 2026 Dec 8, 2020 N/A· v4 7.7 HIGH· v3 5.0 MEDIUM· v2 omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before version 1.0.1 attackers can fake their email address during authentication. This vulnerability impacts a...Show more |
1Ibm 1Resilient Security Orchestration Automation And Response Jun 17, 2026 Oct 29, 2020 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP address. IBM X-Force ID: 190567. |
1Free 2Freebox Server Freebox V5 FirmwareJun 17, 2026 Oct 19, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3. |
1Mcafee 1Mvision Endpoint Detection And Response Jun 17, 2026 Oct 15, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 may allow local administrators to execute malicious code via stopping a core Windows service leaving M...Show more |
Improperly implemented security check in McAfee Active Response (MAR) prior to 2.4.4 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an...Show more |
1Qualcomm 3Atheros Ar9132 Firmware Atheros Ar9283 FirmwareAtheros Ar9285 FirmwareJun 17, 2026 Sep 30, 2020 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router w...Show more |