An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enabl
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blind
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versio
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed c
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a ne
The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This all
Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Device Imperson
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish H
An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE
An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute
DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a f
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6, ma
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing un
The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to
An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. T
Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and p
OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrat
Authentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may aff
Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: befor
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w
A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out d
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to
An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address ver
There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service co
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in
In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the se
Jellyfin is an open source self hosted media server. In versions 10.9.0 to before 10.10.7, the /System/Restart endpoint
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address t
Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caid
On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. U
An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection be
Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing
Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox E
1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauth
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are sup
Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed b
A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown
A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a poten
Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuratio
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user I
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
Frequently Asked Questions
What is CWE-290?
CWE-290 (CWE-290) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-290?
There are 775 CVE records associated with CWE-290 in our database. Of these, 111 are critical severity, 210 are high severity, and 300 are medium severity.
How can I protect against CWE-290 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-290 using AI-powered security agents.
Detect CWE-290 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-290 vulnerabilities across your infrastructure.
Get Started