Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsi
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authenti
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execu
An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP head
The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code an
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vuln
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Al
omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before vers
Authentication Bypass by Spoofing in org.onosproject.acl (access control) and org.onosproject.mobility (host mobility) i
A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC add
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP
When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML doc
A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Mi
A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
Improperly implemented security check in McAfee Active Response (MAR) prior to 2.4.4 may allow local administrators to e
Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 ma
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spo
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may
A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially craf
A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending
A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RT
A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA d
The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by s
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in
OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about t
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP tr
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can di
After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification th
IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Mod
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: a
In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages o
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attack
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the appl
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into t
MailMate before 1.11.3 mishandles a suspicious HTML/MIME structure in a signed/encrypted email.
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be sus
A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerabi
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user
SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerabl
A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native
Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass
A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions,
Cache Poisoning issue exists in DNS Response Rate Limiting.
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a val
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic
SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an att
A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spo
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofi
Frequently Asked Questions
What is CWE-290?
CWE-290 (CWE-290) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-290?
There are 775 CVE records associated with CWE-290 in our database. Of these, 111 are critical severity, 210 are high severity, and 300 are medium severity.
How can I protect against CWE-290 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-290 using AI-powered security agents.
Detect CWE-290 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-290 vulnerabilities across your infrastructure.
Get Started