CWE-451— User Interface Misrepresentation of Critical Information
75 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-451page 1 of 2
- CVE-2020-10775MEDIUMCVSS 5.3EG 5.32020-08-24
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in thei…
- CVE-2020-7363MEDIUMCVSS 4.3EG 4.32020-10-20
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser…
- CVE-2020-7364MEDIUMCVSS 4.3EG 4.32020-10-20
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser…
- CVE-2020-7369MEDIUMCVSS 4.3EG 4.32020-10-20
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Yandex Browser…
- CVE-2020-7370MEDIUMCVSS 4.3EG 4.32020-10-20
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bolt Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the B…
- CVE-2020-7371MEDIUMCVSS 4.3EG 4.32020-10-20
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser v…
- CVE-2020-9236HIGHCVSS 8.8EG 8.82024-12-27
There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers can exploit this vulnerability to perform malicious operatation to comp…
- CVE-2021-22866HIGHCVSS 8.8EG 8.82021-05-14
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this v…
- CVE-2021-27414MEDIUMCVSS 5.5EG 6.12022-03-11
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather auth…
- CVE-2021-27773MEDIUMCVSS 4.2EG 4.32022-05-12
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
- CVE-2021-33593MEDIUMCVSS 5.3EG 5.32021-11-02
Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing.
- CVE-2021-41598HIGHCVSS 8.8EG 8.82022-01-25
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this v…
- CVE-2022-20530MEDIUMCVSS 5.3EG 5.32022-12-16
In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information disclosure of call logs with no additional execution privileges needed. User interaction is not needed for exploitation…
- CVE-2022-22762MEDIUMCVSS 4.3EG 4.32022-12-22
Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This could have been abused to trick the user. <br>*This bug only affects Firefox for Android. Other opera…
- CVE-2022-23646MEDIUMCVSS 5.9EG 5.92022-02-17
Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User Interface (UI) Misrepresentation of Critical Information. In order to be affected, the `next.config.js` file must have an…
- CVE-2022-26383MEDIUMCVSS 4.3EG 4.32022-12-22
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
- CVE-2022-2800MEDIUMCVSS 4.3EG 6.12022-08-12
A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality. The manipulation leads to clickjacking. The attack may be launched remotely…
- CVE-2022-32816MEDIUMCVSS 6.5EG 6.52022-09-23
The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.
- CVE-2022-3313MEDIUMCVSS 6.5EG 6.52022-11-01
Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2022-34479MEDIUMCVSS 6.5EG 6.52022-12-22
A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for Linux. Other …
- CVE-2022-38163LOWCVSS 3.5EG 3.52022-11-07
A Drag and Drop spoof vulnerability was discovered in F-Secure SAFE Browser for Android and iOS version 19.0 and below. Drag and drop operation by user on address bar could lead to a spoofing of the address bar.
- CVE-2022-39258HIGHCVSS 8.1EG 8.12022-09-27
mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect a victim to an attacker controller place to steal Swagger a…
- CVE-2022-45404MEDIUMCVSS 6.5EG 6.52022-12-22
Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability…
- CVE-2023-0130MEDIUMCVSS 6.5EG 6.52023-01-10
Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-0700MEDIUMCVSS 6.5EG 6.52023-02-07
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-2937MEDIUMCVSS 4.3EG 4.32023-05-30
Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium…
- CVE-2023-2938MEDIUMCVSS 4.3EG 4.32023-05-30
Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium…
- CVE-2023-2941MEDIUMCVSS 4.3EG 4.32023-05-30
Inappropriate implementation in Extensions API in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to spoof the contents of the UI via a crafted Chrome Extension. (Chromium secu…
- CVE-2023-4956MEDIUMCVSS 6.5EG 6.52023-11-07
A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it…
- CVE-2023-50938MEDIUMCVSS 6.5EG 6.52024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click …
- CVE-2023-7011MEDIUMCVSS 6.5EG 6.52024-07-16
Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-7281MEDIUMCVSS 4.3EG 4.32024-09-23
Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-7282MEDIUMCVSS 4.3EG 4.32024-09-23
Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security seve…
- CVE-2024-0750HIGHCVSS 8.8EG 8.82024-01-23
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
- CVE-2024-0805MEDIUMCVSS 4.3EG 4.32024-01-24
Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
- CVE-2024-22455MEDIUMCVSS 4.4EG 4.62024-02-14
Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to …
- CVE-2024-23708HIGHCVSS 7.8EG 9.82024-05-07
In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privile…
- CVE-2024-2631MEDIUMCVSS 4.3EG 4.32024-03-20
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- CVE-2024-30055MEDIUMCVSS 5.4EG 5.42024-05-14
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2024-38082MEDIUMCVSS 4.7EG 4.72024-06-20
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2024-38093MEDIUMCVSS 4.3EG 4.32024-06-20
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2024-38112HIGHCVSS 7.5EG 9.0⚠ KEV2024-07-09
Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-38197MEDIUMCVSS 6.5EG 6.52024-08-13
Microsoft Teams for iOS Spoofing Vulnerability
- CVE-2024-38313MEDIUMCVSS 4.3EG 4.32024-06-13
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.
- CVE-2024-43461HIGHCVSS 8.8EG 8.8⚠ KEV2024-09-10
Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-47044MEDIUMCVSS 5.3EG 5.32024-09-26
Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identif…
- CVE-2024-49040HIGHCVSS 7.5EG 7.52024-11-12
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2024-4950MEDIUMCVSS 6.5EG 5.32024-05-15
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity:…
- CVE-2024-51749LOWCVSS 3.5EG 3.52024-11-12
Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to eve…
- CVE-2024-52269HIGHCVSS 8.1EG 8.12024-12-04
User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The SaaS AI assistant ignores hidden content that is rendered after signing, misleading the user. For reference see: CVE-2024…
Map vulnerabilities like CWE-451 to your infrastructure
EchelonGraph correlates every CVE — across CWE-451 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →