This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Volume of CVEs assigned to CWE-290 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
632 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4358CRITICAL In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality v | May 29, 2024 | 9.8 | 99 | YES | YES |
CVE-2022-24112CRITICAL An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulne | Feb 11, 2022 | 9.8 | 99 | YES | YES |
CVE-2022-23131CRITICAL In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session w | Jan 13, 2022 | 9.8 | 97 | YES | YES |
CVE-2024-54085CRITICAL AMI’s SPx contains
a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation
of this vulnerabili | Mar 11, 2025 | 9.8 | 92 | YES | NO |
CVE-2021-29441CRITICAL Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.c | Apr 27, 2021 | 9.8 | 79 | NO | YES |
CVE-2020-7388CRITICAL Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential vali | Jul 22, 2021 | 9.8 | 78 | NO | YES |
CVE-2021-31195HIGH Microsoft Exchange Server Remote Code Execution Vulnerability | May 11, 2021 | 8.8 | 78 | NO | YES |
CVE-2023-50224MEDIUM TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information o | May 3, 2024 | 6.5 | 72 | YES | NO |
CVE-2021-34646CRITICAL Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a r | Aug 30, 2021 | 9.8 | 71 | NO | YES |
CVE-2025-49002CRITICAL DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to | Jun 3, 2025 | 9.8 | 68 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.