Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-290

MITRE ↗

CWE-290

111
CRITICAL
210
HIGH
300
MEDIUM
23
LOW
675 CVEs · Page 7/14
4.0
CVE-2025-26421

In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local

3.4
CVE-2025-13015

Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.

3.3
CVE-2025-26419

In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This

3.2
CVE-2025-26428

In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code

3.1
CVE-2025-65046

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2025-22271

The application or its infrastructure allows for IP address spoofing by providing its own value in the "X-Forwarded-For"

CVE-2025-31122

scratch-coding-hut.github.io is the website for Coding Hut. In 1.0-beta3 and earlier, the login link can be used to logi

CVE-2025-46345

Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify t

CVE-2025-34053

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr(

CVE-2025-34063

A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure o

CVE-2025-34065

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr(

CVE-2025-7448

Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the

CVE-2025-61778

Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0

CVE-2025-9265

A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user ver

CVE-2025-11843

Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an accoun

CVE-2025-12414

An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email addr

CVE-2025-27389

A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this is

CVE-2025-13953

Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active D

CVE-2025-36754

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication check

9.9
CVE-2024-6678

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 pr

9.8
CVE-2023-51350

A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code v

9.8
CVE-2024-29006

By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an A

9.8
CVE-2024-4358 KEV

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gai

9.8
CVE-2024-46957

Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because

9.8
CVE-2024-13061

The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Alth

9.6
CVE-2024-23674

The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication byp

9.6
CVE-2024-12108

In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public

9.4
CVE-2024-23832

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for aut

9.4
CVE-2024-54450

An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentica

9.1
CVE-2024-27349

Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: f

9.1
CVE-2024-37082

When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be po

9.1
CVE-2023-48396

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can

9.1
CVE-2024-51504

When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofin

8.8
CVE-2024-20674

Windows Kerberos Security Feature Bypass Vulnerability

8.8
CVE-2024-34145

A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jen

8.8
CVE-2024-44104

An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Iva

8.8
CVE-2024-36466

A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin p

8.4
CVE-2024-30191

A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0T

8.3
CVE-2024-1555

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulne

8.2
CVE-2024-22519

An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted da

8.2
CVE-2024-22520

An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of cra

8.1
CVE-2024-33531

cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc

8.1
CVE-2024-41107

The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments wh

7.7
CVE-2024-22092

in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, althoug

7.5
CVE-2023-44117

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerab

7.5
CVE-2023-4566

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerab

7.5
CVE-2024-5037

A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to byp

7.5
CVE-2024-39350

A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-m

7.5
CVE-2023-28452

An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a

7.5
CVE-2023-30464

CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.

Frequently Asked Questions

What is CWE-290?

CWE-290 (CWE-290) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-290?

There are 775 CVE records associated with CWE-290 in our database. Of these, 111 are critical severity, 210 are high severity, and 300 are medium severity.

How can I protect against CWE-290 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-290 using AI-powered security agents.

Detect CWE-290 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-290 vulnerabilities across your infrastructure.

Get Started