Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-addres
Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerabili
Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue a
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique a
The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentia
AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP h
Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnera
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers co
A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permiss
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server use
** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions.
An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS ser
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of
Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web
A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of
Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Midd
An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring an
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n
The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over P
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address o
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) t
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrom
Windows DNS Spoofing Vulnerability
Microsoft Excel Spoofing Vulnerability
Authentication Bypass by Spoofing vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01
PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and us
An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address
Microsoft OneNote Spoofing Vulnerability
There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause pa
The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint
The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows att
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated a
Microsoft Edge (Chromium-based) Spoofing Vulnerability
An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco
Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthentic
In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, be
An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 5E1
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-par
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-par
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-par
An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to tr
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft OneNote Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Frequently Asked Questions
What is CWE-290?
CWE-290 (CWE-290) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-290?
There are 775 CVE records associated with CWE-290 in our database. Of these, 111 are critical severity, 210 are high severity, and 300 are medium severity.
How can I protect against CWE-290 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-290 using AI-powered security agents.
Detect CWE-290 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-290 vulnerabilities across your infrastructure.
Get Started