Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

631 CVEs tagged with CWE-290107 Critical, 200 High, 296 Medium, 25 Low, 3 Unrated.

CVE-2021-25827

Published Jun 28, 2023

Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-27964

Published Jun 23, 2023

An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 5E133. When your headphones are seeking a connection request t…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-3128

Published Jun 22, 2023

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-34167

Published Jun 19, 2023

Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them fr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34160

Published Jun 19, 2023

Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them fr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34158

Published Jun 19, 2023

Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them fr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34157

Published Jun 16, 2023

Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-2807

Published Jun 13, 2023

Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2001

Published Jun 7, 2023

An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25743

Published Jun 2, 2023

A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects Firefox Focus. Other versions…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2887

Published May 25, 2023

Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-48349

Published Mar 27, 2023

The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentiality and availability.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-0816

Published Mar 27, 2023

The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-4550

Published Feb 27, 2023

The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 426-450 of 631 CVEsPage 18 of 26