Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

631 CVEs tagged with CWE-290107 Critical, 200 High, 296 Medium, 25 Low, 3 Unrated.

CVE-2024-37082

Published Jul 3, 2024

When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authenticati…

CVSS 9.1 · Critical

CVE-2024-31802

Published Jun 27, 2024

DESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code.

CVSS 6.3 · Medium

CVE-2024-4846

Published Jun 25, 2024

Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39337

Published Jun 24, 2024

Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.

CVSS 6.5 · Medium

CVE-2024-21518

Published Jun 22, 2024

This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path,…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36588

Published Jun 13, 2024

An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.

CVSS 6.5 · Medium

CVE-2024-5812

Published Jun 11, 2024

A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a s…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-52176

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: f…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-51667

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in FeedbackWP Rate my Post – WP Rating System allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ra…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51543

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51542

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in WPMU DEV Branda allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Branda: from n/a through 3.4.…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-49741

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in wpdevart Coming soon and Maintenance mode allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Com…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2023-48753

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in 10up Restricted Site Access allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Restricted Site A…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-48271

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in yonifre Maspik – Spam blacklist allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maspik – Spam…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-47769

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in WP Maintenance allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Maintenance: from n/a throu…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2023-41134

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in pluginkollektiv Antispam Bee allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Antispam Bee: fr…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-40332

Published Jun 4, 2024

Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-37865

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affe…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-4358

Published May 29, 2024

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
62.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-32827

Published May 17, 2024

Authentication Bypass by Spoofing vulnerability in RafflePress Giveaways and Contests allows Functionality Bypass.This issue affects Giveaways and Contests: from n/a through 1.12.…

CVSS 5.3 · Medium
Showing 326-350 of 631 CVEsPage 14 of 26