Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

629 CVEs tagged with CWE-290107 Critical, 200 High, 295 Medium, 25 Low, 2 Unrated.

CVE-2026-0890

Published Jan 13, 2026

Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVSS 5.4 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2025-11250

Published Jan 13, 2026

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62235

Published Jan 10, 2026

Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor. T…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60538

Published Jan 9, 2026

A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-21894

Published Jan 8, 2026

n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthentica…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-69203

Published Jan 1, 2026

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68644

Published Dec 21, 2025

Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a…

CVSS 7.4 · High

CVE-2025-59385

Published Dec 16, 2025

An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36754

Published Dec 13, 2025

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there…

CVSS 9.3 · Critical

CVE-2024-8273

Published Dec 11, 2025

Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13953

Published Dec 10, 2025

Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active Directory (LDAP) login method. Authentication is performed…

CVSS 9.3 · Critical

CVE-2025-66508

Published Dec 9, 2025

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.14 and below use Gin's default configuration which trusts all IP addresses as proxies (…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66507

Published Dec 9, 2025

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66570

Published Dec 5, 2025

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66270

Published Dec 5, 2025

The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, K…

CVSS 4.7 · Medium

CVE-2025-27389

Published Dec 5, 2025

A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this issue may cause the risk detection mechanism to fail, which c…

CVSS 5.1 · Medium

CVE-2025-54305

Published Dec 4, 2025

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates u…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 629 CVEsPage 7 of 26