Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

630 CVEs tagged with CWE-290107 Critical, 200 High, 295 Medium, 25 Low, 3 Unrated.

CVE-2024-39341

Published Sep 23, 2024

Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e.…

CVSS 5.9 · Medium

CVE-2024-45453

Published Sep 23, 2024

Authentication Bypass by Spoofing vulnerability in Peter Hardy-vanDoorn Maintenance Redirect jf3-maintenance-mode.This issue affects Maintenance Redirect: from n/a through <= 2.0.…

CVSS 3.7 · Low

CVE-2023-30464

Published Sep 18, 2024

CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28452

Published Sep 18, 2024

An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8908

Published Sep 17, 2024

Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security sever…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6678

Published Sep 12, 2024

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, whic…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-44104

Published Sep 10, 2024

An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) al…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8399

Published Sep 3, 2024

Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43944

Published Aug 29, 2024

Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation allows Identity Spoofing.This i…

CVSS 3.7 · Low

CVE-2024-7745

Published Aug 28, 2024

In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verific…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42364

Published Aug 23, 2024

Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38807

Published Aug 23, 2024

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signat…

CVSS 6.3 · Medium

CVE-2024-7981

Published Aug 21, 2024

Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35539

Published Aug 19, 2024

Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the sp…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35538

Published Aug 19, 2024

Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41432

Published Aug 7, 2024

An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, sp…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48396

Published Jul 30, 2024

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secr…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-27853

Published Jul 29, 2024

This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41107

Published Jul 19, 2024

The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initia…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40702

Published Jul 9, 2024

PingOne MFA Integration Kit contains a vulnerability where the skipMFA action can be configured such that user authentication does not require the second factor authentication fro…

CVSS 7.7 · High

CVE-2023-40356

Published Jul 9, 2024

PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under certain conditions, this configuration could allow for a new MF…

CVSS 8.7 · High

CVE-2024-37430

Published Jul 9, 2024

Authentication Bypass by Spoofing vulnerability in patreon Patreon WordPress patreon-connect.This issue affects Patreon WordPress: from n/a through <= 1.9.0.

CVSS 5.3 · Medium

CVE-2024-6163

Published Jul 8, 2024

Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37082

Published Jul 3, 2024

When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authenticati…

CVSS 9.1 · Critical
Showing 301-325 of 630 CVEsPage 13 of 26