Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access req
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firef
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_se
OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verifi
OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes,
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook
Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of D
The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Ta
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox
Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upst
OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mu
The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.
Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue
Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address heade
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper i
The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal po
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts clien
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST
In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to
Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been i
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.7` throug
A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34).
Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofi
n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to
n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger
Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects
In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with
Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_da
MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an authenticated user can bypass sandb
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check an
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability i
Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users
Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a user in one workspace could exercise an
Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Go
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attac
Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID
Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baile
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's ku
Frequently Asked Questions
What is CWE-290?
CWE-290 (CWE-290) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-290?
There are 775 CVE records associated with CWE-290 in our database. Of these, 111 are critical severity, 210 are high severity, and 300 are medium severity.
How can I protect against CWE-290 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-290 using AI-powered security agents.
Detect CWE-290 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-290 vulnerabilities across your infrastructure.
Get Started