Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

629 CVEs tagged with CWE-290107 Critical, 200 High, 295 Medium, 25 Low, 2 Unrated.

CVE-2020-26276

Published Dec 17, 2020

Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28856

Published Dec 14, 2020

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-F…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26254

Published Dec 8, 2020

omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before version 1.0.1 attackers can fake their email address during aut…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7326

Published Oct 15, 2020

Improperly implemented security check in McAfee Active Response (MAR) prior to 2.4.4 may allow local administrators to execute malicious code via stopping a core Windows service l…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5354

Published Sep 30, 2020

The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. When the client is conf…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5353

Published Sep 30, 2020

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-16250

Published Aug 26, 2020

HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5415

Published Aug 12, 2020

Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-2033

Published Jun 10, 2020

When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1331

Published Jun 9, 2020

A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System C…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1329

Published Jun 9, 2020

A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Microsoft Bing Search Spoofing Vulnerability'.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10135

Published May 19, 2020

Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication w…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-2002

Published May 13, 2020

An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of th…

CVSS 8.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-4421

Published May 6, 2020

IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11015

Published Apr 30, 2020

A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC address can be spoofed. This means initial registration reques…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 551-575 of 629 CVEsPage 23 of 26