Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extr
The Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#vali
The AWS ALB Route Directive Adapter For Istio repo https://github.com/awslabs/aws-alb-route-directive-adapter-for-istio
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confide
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. When us
Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can
This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace
Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter h
Dell Secure Connect Gateway 5.20 contains an improper authentication vulnerability during the SRS to SCG update path. A
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the con
KernelSU is a Kernel-based root solution for Android devices. In versions 0.7.1 and prior, the logic of get apk path in
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another we
An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive inf
TP-Link TL-WR902AC loginFs Improper Authentication Information Disclosure Vulnerability. This vulnerability allows netwo
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows ne
An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneousl
Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerabil
Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Tra
A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full scr
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox <
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical acce
HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to imper
Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker
DESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code.
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature v
Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow spe
A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6
A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0T
An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary co
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of anot
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof se
Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.
Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that
A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thre
A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thre
A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco
This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 and iPadOS 17. A 3D mo
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ven
All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via t
Microsoft Edge (Chromium-based) Spoofing Vulnerability
An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows un
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apa
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by imprope
Frequently Asked Questions
What is CWE-290?
CWE-290 (CWE-290) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-290?
There are 775 CVE records associated with CWE-290 in our database. Of these, 111 are critical severity, 210 are high severity, and 300 are medium severity.
How can I protect against CWE-290 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-290 using AI-powered security agents.
Detect CWE-290 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-290 vulnerabilities across your infrastructure.
Get Started