Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-290

Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

632
Assigned CVEs
65th
Commonality Rank
7.1
Avg CVSS
0.8%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-290 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 1998
28 years ago
Most Recent CVE
Jul 24, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

632 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-4358CRITICAL
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality v
May 29, 20249.899YESYES
CVE-2022-24112CRITICAL
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulne
Feb 11, 20229.899YESYES
CVE-2022-23131CRITICAL
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session w
Jan 13, 20229.897YESYES
CVE-2024-54085CRITICAL
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerabili
Mar 11, 20259.892YESNO
CVE-2021-29441CRITICAL
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.c
Apr 27, 20219.879NOYES
CVE-2020-7388CRITICAL
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential vali
Jul 22, 20219.878NOYES
CVE-2021-31195HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
May 11, 20218.878NOYES
CVE-2023-50224MEDIUM
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information o
May 3, 20246.572YESNO
CVE-2021-34646CRITICAL
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a r
Aug 30, 20219.871NOYES
CVE-2025-49002CRITICAL
DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to
Jun 3, 20259.868NOYES
View all 632 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
9%
10%
4.0-4.9
18%
19%
5.0-5.9
18%
16%
6.0-6.9
19%
26%
7.0-7.9
13%
11%
8.0-8.9
21%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
5 CVEs
0.8% of CVEs· 89th percentile
Metasploit
3 CVEs
0.5% of CVEs· 83rd percentile
Nuclei
9 CVEs
1.4% of CVEs· 87th percentile
ExploitDB
6 CVEs
0.9% of CVEs· 81st percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products