Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

631 CVEs tagged with CWE-290107 Critical, 200 High, 296 Medium, 25 Low, 3 Unrated.

CVE-2024-32708

Published May 17, 2024

Authentication Bypass by Spoofing vulnerability in helderk Maintenance Mode allows Functionality Bypass.This issue affects Maintenance Mode: from n/a through 3.0.1.

CVSS 3.7 · Low

CVE-2024-33917

Published May 17, 2024

Authentication Bypass by Spoofing vulnerability in webtechideas WTI Like Post allows Functionality Bypass.This issue affects WTI Like Post: from n/a through 1.4.6.

CVSS 5.3 · Medium

CVE-2024-30522

Published May 17, 2024

Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0.

CVSS 5.3 · Medium

CVE-2024-30480

Published May 17, 2024

Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2.

CVSS 3.7 · Low

CVE-2024-30479

Published May 17, 2024

Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows Functionality Bypass.This issue affects IP Blocker Lite: from n/a through 11.1.1.

CVSS 5.3 · Medium

CVE-2024-25906

Published May 17, 2024

Authentication Bypass by Spoofing vulnerability in WP Happy Coders Comments Like Dislike allows Functionality Bypass.This issue affects Comments Like Dislike: from n/a through 1.2…

CVSS 4.3 · Medium

CVE-2024-25595

Published May 17, 2024

Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from n/a through 4.4.1.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22139

Published May 17, 2024

Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress Manutenção allows Functionality Bypass.This issue affects WordPress Manutenção: from n/a through 1.0.6.

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2024-21746

Published May 17, 2024

Authentication Bypass by Spoofing vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Identity Spoofing.This issue affects Wp Ultimate Review: from n/a through <=…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-32977

Published May 14, 2024

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated at…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22364

Published May 3, 2024

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input. A remote attacker coul…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50224

Published May 3, 2024

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
52.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-34145

Published May 2, 2024

A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1347

Published Apr 25, 2024

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33531

Published Apr 24, 2024

cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc header with the value A256GCM.

CVSS 8.1 · High

CVE-2024-27349

Published Apr 22, 2024

Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade t…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-3843

Published Apr 17, 2024

Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security seve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31784

Published Apr 16, 2024

An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the src component.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31863

Published Apr 9, 2024

Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recomme…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30191

Published Apr 9, 2024

A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1…

CVSS 8.4 · High

CVE-2024-30190

Published Apr 9, 2024

A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1…

CVSS 6.1 · Medium
Showing 351-375 of 631 CVEsPage 15 of 26