VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (677)

page 29 of 34
  • CVE-2025-5605MedOct 24, 2025
    risk 0.28cvss 4.3epss 0.01

    An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information…

  • CVE-2025-32275MedApr 10, 2025
    risk 0.28cvss 4.3epss 0.00

    Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker survey-maker allows Identity Spoofing.This issue affects Survey Maker: from n/a through <= 5.1.6.3.

  • CVE-2025-32227MedApr 10, 2025
    risk 0.28cvss 4.3epss 0.00

    Authentication Bypass by Spoofing vulnerability in Asgaros Asgaros Forum asgaros-forum allows Identity Spoofing.This issue affects Asgaros Forum: from n/a through <= 3.0.0.

  • CVE-2024-11701MedNov 26, 2024
    risk 0.28cvss 4.3epss 0.00

    The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.

  • CVE-2024-11692MedNov 26, 2024
    risk 0.28cvss 4.3epss 0.00

    An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

  • CVE-2024-8908MedSep 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2024-7981MedAug 21, 2024
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2024-25906MedMay 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Authentication Bypass by Spoofing vulnerability in WP Happy Coders Comments Like Dislike allows Functionality Bypass.This issue affects Comments Like Dislike: from n/a through 1.2.2.

  • CVE-2024-1347MedApr 25, 2024
    risk 0.28cvss 4.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain…

  • CVE-2024-3843MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-31863MedApr 9, 2024
    risk 0.28cvss 5.3epss 0.01

    Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

  • CVE-2023-42843MedFeb 21, 2024
    risk 0.28cvss 4.3epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.

  • CVE-2023-38173MedJul 21, 2023
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge for Android Spoofing Vulnerability

  • CVE-2023-36883MedJul 14, 2023
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge for iOS Spoofing Vulnerability

  • CVE-2023-2001MedJun 7, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download…

  • CVE-2023-29334MedApr 28, 2023
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2023-21794MedFeb 14, 2023
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2022-1495MedJul 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a remote attacker to spoof the APK downloads dialog via a crafted HTML page.

  • CVE-2022-1307MedJul 25, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-1306MedJul 25, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.