CWE-451
User Interface (UI) Misrepresentation of Critical Information
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
340 vulnerabilities with CWE-451
CVE-2025-43327
MEDIUM
Safari < 26.0 - Address Bar Spoofing via Malicious Website
CVSS 6.5
CVE-2025-9867
MEDIUM
Google Chrome < 140.0.7339.80 - UI Spoofing via Crafted HTML Page
CVSS 5.4
CVE-2025-9865
MEDIUM
Google Chrome <140.0.7339.80 - SSRF
CVSS 5.4
CVE-2025-9491
HIGH
Windows 11 23H2 - Remote Code Execution via LNK File UI Misrepresentation
CVSS 7.8
CVE-2025-9186
MEDIUM
Firefox < 142.0 - Address Bar Spoofing
CVSS 6.5
CVE-2025-9183
MEDIUM
Firefox < 142.0 and 140.2-140.* - Address Bar Spoofing
CVSS 6.5
CVE-2025-8364
MEDIUM
Firefox < 141.0 - URL Spoofing via Blob URI
CVSS 4.3
CVE-2025-8041
MEDIUM
Firefox < 141.0 - URL Origin Misrepresentation in Address Bar
CVSS 5.3
CVE-2025-49755
MEDIUM
Microsoft Edge for Android - Info Disclosure
CVSS 4.3
CVE-2025-8583
MEDIUM
Google Chrome < 139.0.7258.66 - UI Spoofing via Permissions Implementation
CVSS 4.3
CVE-2025-43228
MEDIUM
Safari < 18.6 - Address Bar Spoofing via Malicious Website
CVSS 4.3
CVE-2025-43712
LOW
JHipster < 8.9.0 - Privilege Escalation via Authorities Parameter Manipulation
CVSS 2.9
CVE-2025-8043
CRITICAL
Firefox < 141.0 - URL Truncation Misrepresentation
CVSS 9.8
CVE-2025-47964
MEDIUM
Microsoft Edge Chromium < 138.0.3351.55 - Spoofing
CVSS 5.4
CVE-2025-47963
MEDIUM
Microsoft Edge Chromium < 138.0.3351.55 - Spoofing via UI Misrepresentation
CVSS 6.3
CVE-2025-7021
MEDIUM
OpenAI Operator SaaS - Info Disclosure
CVSS 6.5
CVE-2025-5986
MEDIUM
Thunderbird < 128.11.1 and 128.11.1-128.* and >=139.0.2 - Unauthenticated Arbitrary File Download via Crafted HTML Email
CVSS 6.5
CVE-2025-5066
MEDIUM
Google Chrome < 137.0.7151.55 - UI Spoofing via Crafted HTML Page
CVSS 6.5
CVE-2025-5065
MEDIUM
Google Chrome < 137.0.7151.55 - UI Spoofing via FileSystemAccess API
CVSS 6.5
CVE-2025-29825
MEDIUM
Microsoft Edge Chromium < 136.0.3240.50 - User Interface Misrepresentation of Critical Information
CVSS 6.5
CVE-2025-3859
MEDIUM
Mozilla Firefox Focus < 138.0 - User Interface Misrepresentation via URL Eliding
CVSS 6.1
CVE-2025-4086
MEDIUM
Thunderbird for Android - Info Disclosure
CVSS 6.5
CVE-2025-46394
LOW
BusyBox < 1.37.0 - User Interface Misrepresentation of Filenames via Terminal Escape Sequences
CVSS 3.2
CVE-2025-3523
MEDIUM
Thunderbird < 137.0.2-< 128.9.2 - Info Disclosure
CVSS 6.4
CVE-2025-32371
MEDIUM
DNN - Info Disclosure
CVSS 4.3
Details
Vulnerabilities
340