Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

630 CVEs tagged with CWE-290107 Critical, 200 High, 295 Medium, 25 Low, 3 Unrated.

CVE-2024-54450

Published Dec 27, 2024

An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forge…

CVSS 9.4 · Critical

CVE-2024-55470

Published Dec 20, 2024

Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the ap…

CVSS 7.5 · High

CVE-2023-41133

Published Dec 13, 2024

Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows Functionality Bypass.This issue affects Secure Admin IP: from n/a through 2.0.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-50380

Published Dec 2, 2024

Snap One OVRC cloud uses the MAC address as an identifier to provide information when requested. An attacker can impersonate other devices by supplying enumerated MAC addresses an…

CVSS 8.7 · High

CVE-2024-53862

Published Dec 2, 2024

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. When using `--auth-mode=client`, Archived Workflows can be retriev…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36466

Published Nov 28, 2024

A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-11701

Published Nov 26, 2024

The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11692

Published Nov 26, 2024

An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8935

Published Nov 13, 2024

CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man…

CVSS 7.7 · High

CVE-2024-51504

Published Nov 7, 2024

When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-51406

Published Nov 1, 2024

Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn le…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10465

Published Oct 29, 2024

A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thund…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10462

Published Oct 29, 2024

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunder…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8901

Published Oct 22, 2024

The AWS ALB Route Directive Adapter For Istio repo https://github.com/awslabs/aws-alb-route-directive-adapter-for-istio/tree/master provides an OIDC authentication mechanism tha…

CVSS 6.9 · Medium

CVE-2024-10125

Published Oct 22, 2024

The Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#validatetokensignature contains Middleware that can be used in…

CVSS 6.9 · Medium

CVE-2024-49214

Published Oct 14, 2024

QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block lis…

CVSS 5.3 · Medium

CVE-2024-49193

Published Oct 12, 2024

Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant addit…

CVSS 7.5 · High

CVE-2024-45397

Published Oct 11, 2024

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-RTT packets is received and the…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9391

Published Oct 1, 2024

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the ad…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46957

Published Sep 25, 2024

Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.

CVSS 9.8 · Critical
Showing 276-300 of 630 CVEsPage 12 of 26