CWE-1021
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
401 vulnerabilities with CWE-1021
CVE-2026-47723
HIGH
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
CVE-2026-60370
HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-16397
MEDIUM
Mozilla Firefox for Android WebExtensions - Clickjacking
CVSS 6.5
CVE-2026-40957
HIGH
Absolute Secure Access < 14.55 Login Page - Clickjacking Credential Theft
CVSS 7.5
CVE-2026-58595
HIGH
Microsoft Bing App for IOS Spoofing Vulnerability
CVSS 8.1
CVE-2026-59791
LOW
Jetbrains YouTrack < 2026.2.17012 - Improper Restriction of Rendered UI Layers or Frames
CVSS 3.5
CVE-2026-38979
MEDIUM
ajenti <= 2.2.13 - Clickjacking via Missing Anti-Framing Headers
CVSS 5.4
CVE-2026-14142
MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Crafted HTML Page
CVSS 5.4
CVE-2026-14110
MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via DarkMode Implementation
CVSS 4.3
CVE-2026-44727
MEDIUM
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
CVSS 5.4
CVE-2026-12348
HIGH
Address Bar Spoofing in Arc Search for Android (window.open race condition)
CVSS 7.4
CVE-2026-12323
MEDIUM
Mozilla Firefox and Thunderbird - DOM Core and HTML Spoofing
CVSS 5.4
CVE-2026-12322
MEDIUM
Mozilla Firefox and Thunderbird - Widget Gtk Clickjacking
CVSS 5.4
CVE-2026-10733
MEDIUM
Improper Restriction of Rendered UI Layers or Frames in GitLab
CVSS 4.3
CVE-2026-28577
HIGH
Google Android - Improper Restriction of Rendered UI Layers or Frames
CVSS 7.8
CVE-2026-0061
MEDIUM
Android 14-16 WindowState - Tapjacking Privilege Escalation
CVSS 5.9
CVE-2026-0036
HIGH
Android 14-16 StageCoordinator - Tapjacking Privilege Escalation
CVSS 7.8
CVE-2026-21785
MEDIUM
HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security Policy
CVSS 4.0
CVE-2026-9396
LOW
Besen BS20 EV Charging Station Firmware Version Check ui layer
CVSS 3.7
CVE-2026-37470
HIGH
ClipBucket v5 v.5.5.2 - Remote Code Execution via Authentication Interface
CVSS 7.3
CVE-2026-42502
MEDIUM
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
CVSS 6.1
CVE-2026-27136
MEDIUM
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
CVSS 6.1
CVE-2026-25681
MEDIUM
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
CVSS 6.1
CVE-2026-28971
MEDIUM
iOS and iPadOS < 26.5 - UI Layer Restriction Bypass via Malicious Iframe
CVSS 4.3
CVE-2026-8022
LOW
Google Chrome < 148.0.7778.96 - Cross-Origin Data Leak via MHTML
CVSS 3.1
Details
Vulnerabilities
401