VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (747)

page 12 of 38
  • CVE-2024-22092HigApr 2, 2024
    risk 0.50cvss 7.7epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, although these require user action.

  • CVE-2023-22474HigFeb 3, 2023
    risk 0.50cvss 8.7epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server uses the request header `x-forwarded-for` to determine the client IP address. If Parse Server doesn't run behind a proxy server, then a client can set this header…

  • CVE-2022-29218HigMay 13, 2022
    risk 0.50cvss 7.7epss 0.01

    RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`) to be temporarily replaced in the CDN cache by a…

  • CVE-2021-28478HigMay 11, 2021
    risk 0.50cvss 7.6epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2019-16766HigNov 29, 2019
    risk 0.50cvss 8.7epss 0.01

    When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. This problem has been patched in version…

  • CVE-2026-82563HigSep 9, 2026
    risk 0.49cvss 7.6epss 0.00

    An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior.

  • CVE-2026-62759HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

  • CVE-2026-84476HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited…

  • CVE-2026-69183HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before the trust-proxy-derived req.ip value. An…

  • CVE-2026-13207HigJun 30, 2026
    risk 0.49cvss 7.5epss 0.01

    FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot-segment sequences before applying authentication middleware, allowing unauthenticated requests to access…

  • CVE-2026-27089HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.

  • CVE-2026-42674HigJun 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0.

  • CVE-2026-8963HigMay 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

  • CVE-2026-8960HigMay 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

  • CVE-2026-28954HigMay 11, 2026
    risk 0.49cvss 7.5epss 0.00

    A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A maliciously crafted disk image may bypass Gatekeeper checks.

  • CVE-2026-33661HigMar 26, 2026
    risk 0.49cvss 8.6epss 0.01

    Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `verify_wechat_sign()` function in `src/Functions.php` unconditionally skips all signature verification when the PSR-7 request reports `localhost` as the host.…

  • CVE-2026-24372HigMar 25, 2026
    risk 0.49cvss 7.5epss 0.00

    Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10.

  • CVE-2026-32666HigMar 21, 2026
    risk 0.49cvss 7.5epss 0.00

    WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or…

  • CVE-2025-69401HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Authentication Bypass by Spoofing vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Identity Spoofing.This issue affects WooODT Lite: from n/a through <= 2.5.2.

  • CVE-2025-59802HigDec 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF…