Vulnerabilities (CVE)

Filtered by CWE-290
Total 716 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-35392 1 Microsoft 1 Edge Chromium 2026-06-17 N/A 4.7 MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2023-34329 1 Ami 1 Megarac Sp-x 2026-06-17 N/A 9.1 CRITICAL
AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit of this vulnerability may lead to loss of confidentiality, integrity, and availability.
CVE-2023-34167 1 Huawei 1 Emui 2026-06-17 N/A 5.3 MEDIUM
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.
CVE-2023-34160 1 Huawei 1 Emui 2026-06-17 N/A 5.3 MEDIUM
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.
CVE-2023-34158 1 Huawei 1 Emui 2026-06-17 N/A 5.3 MEDIUM
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.
CVE-2023-34157 1 Huawei 1 Harmonyos 2026-06-17 N/A 10.0 CRITICAL
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
CVE-2023-33140 1 Microsoft 1 Onenote 2026-06-17 N/A 6.5 MEDIUM
Microsoft OneNote Spoofing Vulnerability
CVE-2023-32207 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2026-06-17 N/A 8.8 HIGH
A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
CVE-2023-31424 1 Broadcom 1 Brocade Sannav 2026-06-17 N/A 8.1 HIGH
Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.
CVE-2023-30950 1 Palantir 1 Foundry Campaigns 2026-06-17 N/A 6.5 MEDIUM
The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint
CVE-2023-30803 1 Sangfor 1 Next-gen Application Firewall 2026-06-17 N/A 9.8 CRITICAL
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for header.
CVE-2023-30464 1 Coredns.io 1 Coredns 2026-06-17 N/A 7.5 HIGH
CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.
CVE-2023-2887 1 Cbot 2 Cbot Core, Cbot Panel 2026-06-17 N/A 9.8 CRITICAL
Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
CVE-2023-2807 1 Pandorafms 1 Pandora Fms 2026-06-17 N/A 6.4 MEDIUM
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.
CVE-2023-2001 1 Gitlab 1 Gitlab 2026-06-17 N/A 4.3 MEDIUM
An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.
CVE-2023-29334 1 Microsoft 1 Edge Chromium 2026-06-17 N/A 4.3 MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2023-29147 1 Malwarebytes 2 Endpoint Detection And Response, Malwarebytes 2026-06-17 N/A 5.5 MEDIUM
In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier.
CVE-2023-28803 1 Zscaler 1 Client Connector 2026-06-17 N/A 5.9 MEDIUM
An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on Windows, allowing a functionality bypass. This issue affects Client Connector: before 3.9.
CVE-2023-28452 1 Coredns.io 1 Coredns 2026-06-17 N/A 7.5 HIGH
An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.
CVE-2023-27964 1 Apple 1 Airpods Firmware 2026-06-17 N/A 5.4 MEDIUM
An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 5E133. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones.