VulnSea

CWE-290

CVEs classified under CWE-290, newest first.

131 CVEsRSS

CVE-2025-13636Medium· 4.3
9mo ago

Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted domain name

Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted domain name. (Chromium security seve…

▾ Sunlitgoogle · chromeEPSS 0.20%via NVD
CVE-2025-13635Medium· 4.4
9mo ago

Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafted HTML page

Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.15%via NVD
CVE-2025-59699Medium· 6.8
9mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root fi…

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root fi…

▾ Sunlitentrust · nshield_5c_firmwareEPSS 0.33%via NVD
CVE-2025-43503Medium· 4.3
10mo ago

An inconsistent user interface issue was addressed with improved state management

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Visiting a mali…

▾ Sunlitapple · safariEPSS 0.39%via NVD
CVE-2025-43493Medium· 4.3
10mo ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Visiting a malicious website may lead to address bar spoofing.

▾ Sunlitapple · safariEPSS 0.36%via NVD
CVE-2025-54576High· 7.4
1y ago

github.com/oauth2-proxy/oauth2-proxy: OAuth2-Proxy authentication bypass (CVE-2025-54576)

An authentication bypass flaw was found in the OAuth2-Proxy project. This bypass affects systems that have configured their deployment to skip authentication on endpoints that match a deployment-defined regular expression. HTTP parameters …

▾ TwilightRed Hat · Red Hat Ceph Storage 8EPSS 1.2%via CSAF
CVE-2024-30058Medium· 5.4
2y ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

▾ Sunlitmicrosoft · edge_chromiumEPSS 0.40%via NVD
CVE-2023-50224Medium· 6.5CISA KEV0day
2y ago

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Au…

▾ Midnighttp-link · tl-wr841n_firmwareEPSS 16%via NVD
CVE-2020-28856High· 7.5
5y ago

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 1…

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 1…

▾ Twilightopenasset · digital_asset_managementEPSS 2.5%via NVD
CVE-2018-5354High· 8.8PoC
5y ago

The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing

The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. When the client is configured to use HTTP, it does not authenticate the intended …

▾ Midnightanixis · password_reset_clientEPSS 1.9%via NVD
CVE-2018-5353Critical· 9.8PoC
5y ago

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser w…

▾ Abyssalzohocorp · manageengine_adselfservice_plusEPSS 11%via NVD
CWE-290 vulnerabilities (CVEs) — page 5 · VulnSea