Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

631 CVEs tagged with CWE-290107 Critical, 200 High, 296 Medium, 25 Low, 3 Unrated.

CVE-2023-49794

Published Jan 2, 2024

KernelSU is a Kernel-based root solution for Android devices. In versions 0.7.1 and prior, the logic of get apk path in KernelSU kernel module can be bypassed, which causes any ma…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50463

Published Dec 10, 2023

The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43304

Published Dec 7, 2023

An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6263

Published Nov 22, 2023

An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legit…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3103

Published Nov 22, 2023

Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Middle (MITM) attack on the robot's camera video stream. In add…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5801

Published Nov 8, 2023

Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28803

Published Oct 23, 2023

An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on Windows, allowing a functionality bypass. This issue affect…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30803

Published Oct 10, 2023

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authenticati…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-44463

Published Oct 2, 2023

An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has no…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4178

Published Sep 5, 2023

Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-31424

Published Aug 31, 2023

Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34329

Published Jul 18, 2023

AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit of this vulnerability may lead…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2022-48513

Published Jul 6, 2023

Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-22814

Published Jul 1, 2023

An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This is…

CVSS 10.0 · Critical
Showing 401-425 of 631 CVEsPage 17 of 26