Vulnerabilities (CVE)

Filtered by CWE-290
Total 370 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-1104 2025-02-07 7.5 HIGH 7.3 HIGH
A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by spoofing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-21415 1 Microsoft 1 Azure Ai Face Service 2025-02-07 N/A 9.9 CRITICAL
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.
CVE-2022-47522 2 Ieee, Sonicwall 59 Ieee 802.11, Soho 250, Soho 250 Firmware and 56 more 2025-02-06 N/A 7.5 HIGH
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.
CVE-2023-51543 1 Metagauss 1 Registrationmagic 2025-02-04 N/A 5.3 MEDIUM
Authentication Bypass by Spoofing vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.2.5.0.
CVE-2023-32207 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2025-01-31 N/A 8.8 HIGH
A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
CVE-2024-54158 1 Jetbrains 1 Youtrack 2025-01-30 N/A 3.5 LOW
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
CVE-2025-24458 1 Jetbrains 1 Youtrack 2025-01-30 N/A 7.1 HIGH
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
CVE-2024-4358 1 Telerik 1 Report Server 2024 2025-01-27 N/A 9.8 CRITICAL
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
CVE-2025-24628 2025-01-27 N/A 5.3 MEDIUM
Authentication Bypass by Spoofing vulnerability in BestWebSoft Google Captcha allows Identity Spoofing. This issue affects Google Captcha: from n/a through 1.78.
CVE-2022-22364 1 Ibm 1 Cognos Controller 2025-01-07 N/A 5.3 MEDIUM
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 220903.
CVE-2023-2001 1 Gitlab 1 Gitlab 2025-01-07 N/A 4.3 MEDIUM
An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.
CVE-2024-12108 2 Microsoft, Progress 2 Windows, Whatsup Gold 2025-01-06 N/A 9.6 CRITICAL
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
CVE-2022-35770 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-01-02 N/A 6.5 MEDIUM
Windows NTLM Spoofing Vulnerability
CVE-2022-34689 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-01-02 N/A 7.5 HIGH
Windows CryptoAPI Spoofing Vulnerability
CVE-2024-13061 2025-01-02 N/A 9.8 CRITICAL
The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.
CVE-2024-54450 2024-12-28 N/A 9.4 CRITICAL
An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header rather than the real IP address that the user logged in from. This fake IP address can later be displayed in the My Account popup that shows the IP address that was used to log in.
CVE-2024-55470 2024-12-20 N/A 7.5 HIGH
Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the issue, as the application relies on client-side information for authentication.
CVE-2024-3843 2 Fedoraproject, Google 2 Fedora, Chrome 2024-12-19 N/A 4.3 MEDIUM
Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-34157 1 Huawei 1 Harmonyos 2024-12-17 N/A 10.0 CRITICAL
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
CVE-2023-41133 2024-12-13 N/A 5.3 MEDIUM
Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows Functionality Bypass.This issue affects Secure Admin IP: from n/a through 2.0.