← Back
CWE-290

690 CVEs • Abstraction: Base

Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

JSON object

Loading...

CVEs (690)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Onap
1Open Network Automation Platform
Jun 17, 2026
Mar 18, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersonate an arbitrary existing user without any authentication. All APPC and...Show more
An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersonate an arbitrary existing user without any authentication. All APPC and SDC setups are affected.Show less
1Opennetworking
1Onos
Jun 17, 2026
Feb 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Authentication Bypass by Spoofing in org.onosproject.acl (access control) and org.onosproject.mobility (host mobility) in ONOS v2.0 and earlier allows attackers to bypass network access control via data plane packet inje...Show more
Authentication Bypass by Spoofing in org.onosproject.acl (access control) and org.onosproject.mobility (host mobility) in ONOS v2.0 and earlier allows attackers to bypass network access control via data plane packet injection. To exploit the vulnerability, an attacker sends a gratuitous ARP reply that causes the host mobility application to remove existing access control flow denial rules in the network. The access control application does not re-install flow deny rules, so the attacker can bypass the intended access control policy.Show less
1Postieplugin
1Postie
Jun 17, 2026
Jan 2, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message.
1Beckhoff
1Twincat
Jun 17, 2026
Dec 19, 2019
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
1Omron
2Plc Cj Firmware
Plc Cs Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.
1Labdigital
1Wagtail 2fa
Jun 17, 2026
Nov 29, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full ac...Show more
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. This problem has been patched in version 1.3.0.Show less
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
1Sap
1Ui
Jun 17, 2026
Nov 13, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.
1Microsoft
1Azure Stack
Jun 17, 2026
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.
4Isc
NicNlnetlabs+1 more
4Bind
Enterprise LinuxKnot Resolver+1 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
Cache Poisoning issue exists in DNS Response Rate Limiting.
1Ready
1Wireless Emergency Alerts
Jun 17, 2026
Nov 2, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Blo...Show more
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12). NOTE: testing inside an RF-isolated shield box suggested that all LTE phones are affected by design (e.g., use of Android versus iOS does not matter); testing in an open RF environment is, of course, contraindicated.Show less
1Microsoft
2Edge
Internet Explorer
Jun 17, 2026
Oct 10, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Oct 10, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.
1Microsoft
2Edge
Internet Explorer
Jun 17, 2026
Oct 10, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.
1Zingbox
1Inspector
Jun 17, 2026
Oct 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoofing.