CWE-290: CWE-290

167
Total CVEs
49
Critical
53
High
7.5
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
17
2025
71
2024
47
2023
15
2022
7

Top Affected Vendors

1 Mozilla 11
2 Google 8
3 Huawei 6
4 Apache 6
5 Microsoft 3
6 Apple 3
7 Coredns.io 2
8 Fit2cloud 2
9 Gitlab 2
10 Canonical 2

All CWE-290 CVEs (167)

CVE-2025-66570
10.0

This vulnerability in cpp-httplib allows attackers to inject HTTP headers (REMOTE_ADDR, REMOTE_PORT, LOCAL_ADDR, LOCAL_PORT) that shadow server-genera...

Dec 5, 2025
CVE-2023-22814
10.0

This vulnerability allows attackers to bypass authentication by spoofing tokens, enabling impersonation attacks on affected My Cloud OS 5 devices. It ...

Jul 1, 2023
CVE-2023-34157
10.0

This vulnerability allows attackers to hijack the HwWatchHealth component on HarmonyOS devices, causing repeated pop-up windows that disrupt normal ap...

Jun 16, 2023
CVE-2022-2310
10.0

CVE-2022-2310 is an authentication bypass vulnerability in Skyhigh Secure Web Gateway (SWG) that allows remote attackers to access the administration ...

Jul 27, 2022
CVE-2020-7388
10.0

CVE-2020-7388 is an unauthenticated remote command execution vulnerability in Sage X3's AdxDSrv.exe component that allows attackers to bypass authenti...

Jul 22, 2021
CVE-2020-26276
10.0

This vulnerability allows attackers to modify trusted SAML responses in Fleet osquery manager, enabling unauthorized logins through SSO authentication...

Dec 17, 2020
CVE-2026-22797
9.9

This vulnerability in OpenStack keystonemiddleware allows authenticated attackers to forge identity headers like X-Is-Admin-Project, X-Roles, or X-Use...

Jan 19, 2026
CVE-2025-21415
9.9

This critical vulnerability in Azure AI Face Service allows attackers to bypass authentication mechanisms by spoofing identity, enabling privilege esc...

Jan 29, 2025
CVE-2024-6678
9.9

This vulnerability in GitLab allows an attacker to trigger CI/CD pipelines as any user under specific conditions, potentially leading to unauthorized ...

Sep 12, 2024
CVE-2026-2800
9.8

A spoofing vulnerability in the WebAuthn component of Firefox for Android allows attackers to potentially impersonate legitimate websites during authe...

Feb 24, 2026
CVE-2026-25938
9.8

An authentication bypass vulnerability in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to execute arbitrary code on the s...

Feb 9, 2026
CVE-2025-59385
9.8

This CVE describes an authentication bypass vulnerability in QNAP operating systems that allows remote attackers to spoof authentication and access re...

Dec 16, 2025
CVE-2025-36753
9.8

The SWD debug interface on Growatt ShineLan-X communication dongles is enabled by default, allowing attackers to gain debug access to extract secrets ...

Dec 13, 2025
CVE-2025-8853
9.8

Official Document Management System by 2100 Technology has an authentication bypass vulnerability that allows unauthenticated remote attackers to obta...

Aug 11, 2025
CVE-2025-36594
9.8

An authentication bypass vulnerability in Dell PowerProtect Data Domain allows unauthenticated remote attackers to create accounts and bypass protecti...

Aug 4, 2025
CVE-2025-43245
9.8

This CVE describes a code-signing downgrade vulnerability in macOS that allows malicious applications to bypass security restrictions and access prote...

Jul 30, 2025
CVE-2023-41591
9.8

CVE-2023-41591 is an authentication bypass vulnerability in ONOS SDN controller that allows attackers to spoof IP/MAC addresses. This enables man-in-t...

May 29, 2025
CVE-2025-32966
9.8

DataEase versions before 2.10.8 contain a vulnerability where authenticated users can achieve remote code execution through the backend JDBC connectio...

Apr 23, 2025
CVE-2024-55210
9.8

This vulnerability allows attackers to bypass multi-factor authentication in TOTVS Framework (Linha Protheus) by sending specially crafted websocket m...

Apr 9, 2025
CVE-2024-54085
KEV EPSS 10.5% 9.8

CVE-2024-54085 is a critical authentication bypass vulnerability in AMI's SPx BMC firmware that allows remote attackers to gain unauthorized access th...

Mar 11, 2025
CVE-2022-3180
9.8

CVE-2022-3180 is an unauthenticated privilege escalation vulnerability in the WPGateway WordPress plugin that allows attackers to create administrator...

Feb 11, 2025
CVE-2024-13061
9.8

The Electronic Official Document Management System from 2100 Technology has an authentication bypass vulnerability that allows unauthenticated remote ...

Dec 31, 2024
CVE-2024-46957
9.8

This vulnerability in Mellium XMPP library allows attackers to spoof responses when predictable IDs are used, because the library fails to verify stan...

Sep 25, 2024
CVE-2024-4358
9.8

An authentication bypass vulnerability in Progress Telerik Report Server allows unauthenticated attackers to access restricted functionality. This aff...

May 29, 2024
CVE-2024-29006
9.8

This vulnerability allows attackers to spoof their IP address using the x-forwarded-for HTTP header, potentially bypassing authentication in CloudStac...

Apr 4, 2024
CVE-2023-51350
9.8

This vulnerability in ujcms v8.0.2 allows remote attackers to spoof IP addresses via the X-Forwarded-For header, potentially leading to information di...

Jan 11, 2024
CVE-2023-30803
9.8

CVE-2023-30803 is an authentication bypass vulnerability in Sangfor Next-Gen Application Firewall NGAF version 8.0.17. Remote unauthenticated attacker...

Oct 10, 2023
CVE-2021-25827
9.8

CVE-2021-25827 is an authentication bypass vulnerability in Emby Server that allows attackers to bypass login requirements by setting the X-Forwarded-...

Jun 28, 2023
CVE-2023-2887
9.8

This CVE describes an authentication bypass vulnerability in CBOT Chatbot that allows attackers to spoof authentication and gain unauthorized access. ...

May 25, 2023
CVE-2022-21142
9.8

CVE-2022-21142 is an authentication bypass vulnerability in a-blog CMS that allows remote unauthenticated attackers to bypass authentication under spe...

Feb 24, 2022
CVE-2022-24112
9.8

CVE-2022-24112 is a critical authentication bypass vulnerability in Apache APISIX's batch-requests plugin that allows attackers to bypass IP restricti...

Feb 11, 2022
CVE-2021-34646
9.8

This vulnerability allows attackers to bypass authentication in the Booster for WooCommerce WordPress plugin by exploiting weak token generation in th...

Aug 30, 2021
CVE-2020-22001
9.8

CVE-2020-22001 is an authentication bypass vulnerability in HomeAutomation 3.3.2 that allows attackers to spoof their IP address using the X-Forwarded...

Apr 27, 2021
CVE-2024-23674
9.6

This vulnerability allows man-in-the-middle attackers to bypass authentication in Germany's Online-Ausweis-Funktion eID scheme, enabling identity thef...

Feb 15, 2024
CVE-2025-25182
9.4

This CVE describes an authentication bypass vulnerability in Stroom data platform when configured with AWS Application Load Balancer (ALB) authenticat...

Feb 12, 2025
CVE-2024-54450
9.4

CVE-2024-54450 is an authentication IP spoofing vulnerability in Kurmi Provisioning Suite where attackers can forge the X-Forwarded-For header to make...

Dec 27, 2024
CVE-2024-23832
9.4

This vulnerability in Mastodon's LDAP authentication allows attackers to impersonate and take over any remote account due to insufficient origin valid...

Feb 1, 2024
CVE-2023-3128
9.4

This vulnerability allows attackers to bypass authentication and take over Grafana accounts when Azure AD OAuth is configured with multi-tenant applic...

Jun 22, 2023
CVE-2025-11250
9.1

This authentication bypass vulnerability in ManageEngine ADSelfService Plus allows attackers to circumvent login protections and gain unauthorized acc...

Jan 13, 2026
CVE-2025-58595
9.1

This vulnerability allows attackers to bypass authentication in the WordPress 'All In One Login' plugin by spoofing identities, enabling unauthorized ...

Nov 6, 2025
CVE-2025-54576
9.1

This vulnerability allows attackers to bypass authentication in OAuth2-Proxy by crafting URLs with query parameters that match regex patterns in the s...

Jul 30, 2025
CVE-2024-51504
9.1

This vulnerability allows attackers to bypass IP-based authentication in ZooKeeper Admin Server by spoofing the X-Forwarded-For HTTP header. It affect...

Nov 7, 2024
CVE-2023-48396
9.1

This CVE describes an authentication bypass vulnerability in Apache SeaTunnel where a hardcoded JWT secret key allows attackers to forge authenticatio...

Jul 30, 2024
CVE-2024-37082
9.1

This vulnerability allows attackers to bypass mTLS authentication to Cloud Foundry applications by crafting specific HTTP requests. It affects deploym...

Jul 3, 2024
CVE-2023-5801
9.1

This vulnerability allows attackers to bypass identity verification in the face unlock module on affected Huawei devices. Successful exploitation coul...

Nov 8, 2023
CVE-2023-34329
9.1

This vulnerability in AMI MegaRAC SPx12 BMC allows attackers to bypass authentication by spoofing HTTP headers, potentially gaining unauthorized acces...

Jul 18, 2023
CVE-2022-23131
9.1

This vulnerability allows unauthenticated attackers to modify session data and escalate privileges to admin access in Zabbix Frontend when SAML SSO au...

Jan 13, 2022
CVE-2021-38598
9.1

This vulnerability in OpenStack Neutron allows attackers controlling a server instance to impersonate hardware addresses (MAC addresses) of other syst...

Aug 23, 2021
CVE-2021-22779
9.1

This vulnerability allows attackers to bypass authentication and gain unauthorized read/write access to industrial controllers by spoofing Modbus comm...

Jul 14, 2021
CVE-2024-8273
8.8

This vulnerability allows attackers to bypass authentication in HYPR Server by spoofing identities, potentially gaining unauthorized access to systems...

Dec 11, 2025

About CWE-290 (CWE-290)

Our database tracks 167 CVEs classified as CWE-290, with 49 rated critical and 53 rated high severity. The average CVSS score for CWE-290 vulnerabilities is 7.5.

External reference: View CWE-290 on MITRE CWE →

Monitor CWE-290 Vulnerabilities

Get alerted when new CWE-290 CVEs affect your infrastructure.

Start Monitoring Free