VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (677)

page 21 of 34
  • CVE-2021-21310MedFeb 11, 2021
    risk 0.40cvss 6.1epss 0.02

    NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database adapter in conjunction with the Email provider are impacted.…

  • CVE-2018-8278MedJul 11, 2018
    risk 0.40cvss 6.1epss 0.06

    A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge.

  • CVE-2026-50141HigJun 18, 2026
    risk 0.39cvss epss 0.00

    Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged `agent_id` value into outgoing gRPC…

  • CVE-2026-41299HigApr 21, 2026
    risk 0.39cvss 7.1epss 0.00

    OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only provenance fields are gated by self-declared client metadata from WebSocket handshake rather than verified authorization state. Authenticated operator clients…

  • CVE-2024-32977HigMay 14, 2024
    risk 0.39cvss 7.1epss 0.01

    OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within…

  • CVE-2023-51747HigFeb 27, 2024
    risk 0.39cvss 7.1epss 0.01

    Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop,…

  • CVE-2023-7169MedFeb 8, 2024
    risk 0.39cvss 6.0epss 0.00

    Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Customers advised to upgrade to version 7.0

  • CVE-2024-0454MedJan 12, 2024
    risk 0.39cvss 6.0epss 0.00

    ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity. Version which is lower than…

  • CVE-2022-34716MedAug 9, 2022
    risk 0.39cvss 5.9epss 0.02

    .NET Spoofing Vulnerability

  • CVE-2020-7327MedOct 15, 2020
    risk 0.39cvss 6.0epss 0.00

    Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state…

  • CVE-2020-7326MedOct 15, 2020
    risk 0.39cvss 6.0epss 0.00

    Improperly implemented security check in McAfee Active Response (MAR) prior to 2.4.4 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MAR failing open rather…

  • CVE-2013-5661MedNov 5, 2019
    risk 0.39cvss 5.9epss 0.03

    Cache Poisoning issue exists in DNS Response Rate Limiting.

  • CVE-2019-1318MedOct 10, 2019
    risk 0.39cvss 5.9epss 0.04

    A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.

  • CVE-2026-6181MedAug 11, 2026
    risk 0.38cvss 5.9epss 0.00

    The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account.

  • CVE-2026-47381MedJun 23, 2026
    risk 0.38cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a user in one workspace could exercise another workspace's integration through the testConnection endpoint by supplying its ID, because the integration was fetched in a bypass scope and the caller's…

  • CVE-2025-46345MedMay 1, 2025
    risk 0.38cvss epss 0.00

    Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper…

  • CVE-2024-20384MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic…

  • CVE-2024-20299MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have…

  • CVE-2024-20297MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have…

  • CVE-2024-39341MedSep 23, 2024
    risk 0.38cvss 5.9epss 0.00

    Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. WebAPI.cfg.xml) after the installation process. This file can be accessed without authentication on…