Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

629 CVEs tagged with CWE-290107 Critical, 200 High, 295 Medium, 25 Low, 2 Unrated.

CVE-2025-27616

Published Mar 10, 2025

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions 0.25.3 and 0.26.3, by spoofing a webhook payload with a sp…

CVSS 8.5 · High

CVE-2025-26696

Published Mar 10, 2025

Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted.…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13685

Published Mar 4, 2025

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their val…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22271

Published Feb 28, 2025

The application or its infrastructure allows for IP address spoofing by providing its own value in the "X-Forwarded-For" header. Thus, the action logging mechanism in the applicat…

CVSS 6.9 · Medium

CVE-2020-6158

Published Feb 21, 2025

Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address…

CVSS 4.7 · Medium

CVE-2023-51327

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51326

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51323

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51321

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25055

Published Feb 18, 2025

Authentication bypass by spoofing issue exists in FileMegane versions above 1.0.0.0 prior to 3.4.0.0, which may lead to user impersonation. If exploited, restricted file contents…

CVSS 5.3 · Medium

CVE-2025-1298

Published Feb 14, 2025

Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.

CVSS 9.8 · Critical

CVE-2025-25182

Published Feb 12, 2025

Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2…

CVSS 9.4 · Critical

CVE-2022-3180

Published Feb 11, 2025

The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2025-1104

Published Feb 7, 2025

A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by sp…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-36557

Published Feb 6, 2025

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023…

CVSS 6.6 · Medium

CVE-2025-24628

Published Jan 27, 2025

Authentication Bypass by Spoofing vulnerability in bestwebsoft Google Captcha google-captcha allows Identity Spoofing.This issue affects Google Captcha: from n/a through <= 1.78.

CVSS 5.3 · Medium

CVE-2024-55925

Published Jan 23, 2025

In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24458

Published Jan 21, 2025

In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0442

Published Jan 15, 2025

Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spo…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-0440

Published Jan 15, 2025

Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium s…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-13061

Published Dec 31, 2024

The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used…

CVSS 9.8 · Critical

CVE-2024-54450

Published Dec 27, 2024

An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forge…

CVSS 9.4 · Critical
Showing 251-275 of 629 CVEsPage 11 of 26