In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local
Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.
In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This
In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code
Microsoft Edge (Chromium-based) Spoofing Vulnerability
The application or its infrastructure allows for IP address spoofing by providing its own value in the "X-Forwarded-For"
scratch-coding-hut.github.io is the website for Coding Hut. In 1.0-beta3 and earlier, the login link can be used to logi
Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify t
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr(
A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure o
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr(
Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the
Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user ver
Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an accoun
An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email addr
A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this is
Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active D
The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication check
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 pr
A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code v
By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an A
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gai
Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because
The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Alth
The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication byp
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for aut
An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentica
Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: f
When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be po
Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofin
Windows Kerberos Security Feature Bypass Vulnerability
A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jen
An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Iva
A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin p
A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0T
When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulne
An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted da
An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of cra
cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc
The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments wh
in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, althoug
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerab
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerab
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to byp
A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-m
An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a
CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.
Frequently Asked Questions
What is CWE-290?
CWE-290 (CWE-290) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-290?
There are 775 CVE records associated with CWE-290 in our database. Of these, 111 are critical severity, 210 are high severity, and 300 are medium severity.
How can I protect against CWE-290 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-290 using AI-powered security agents.
Detect CWE-290 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-290 vulnerabilities across your infrastructure.
Get Started