Microsoft Edge (Chromium-based) Spoofing Vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 bef
Microsoft Edge for iOS Spoofing Vulnerability
Microsoft Edge for Android Spoofing Vulnerability
WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions c
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered i
An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x p
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default co
Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versio
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a m
python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authenticati
An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpa
ActivityWatch open-source automated time tracker. Versions prior to 0.12.0b2 are vulnerable to DNS rebinding attacks. Th
anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens.
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed passwo
Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to FSCT-2022-0062, there is a
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacke
Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. Aft
RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code
Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture AT
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier a
Windows CryptoAPI Spoofing Vulnerability
Microsoft Outlook for Mac Spoofing Vulnerability
A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media file
The authentication mechanism used by technicians on the tested version of Dominion Voting Systems ImageCast X is suscept
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch
Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable t
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote att
Windows NTLM Spoofing Vulnerability
A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could
Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may all
When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted.
.NET Spoofing Vulnerability
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduc
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already
Skype for Business and Lync Spoofing Vulnerability
Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filter
dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This
Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing.
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLA
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/S
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length
The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spo
Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof t
Frequently Asked Questions
What is CWE-290?
CWE-290 (CWE-290) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-290?
There are 775 CVE records associated with CWE-290 in our database. Of these, 111 are critical severity, 210 are high severity, and 300 are medium severity.
How can I protect against CWE-290 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-290 using AI-powered security agents.
Detect CWE-290 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-290 vulnerabilities across your infrastructure.
Get Started