CWE-451
User Interface (UI) Misrepresentation of Critical Information
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
343 vulnerabilities with CWE-451
CVE-2024-30055
MEDIUM
Microsoft Edge Chromium < 124.0.2478.97 - Spoofing
CVSS 5.4
CVE-2024-23708
HIGH
NotificationManagerService - Privilege Escalation
CVSS 7.8
CVE-2024-2631
MEDIUM
Google Chrome < 123.0.6312.58 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2024-0805
MEDIUM
Google Chrome <121.0.6167.85 - CSRF
CVSS 4.3
CVE-2024-0750
HIGH
Firefox < 122.0, Firefox ESR < 115.7, Thunderbird < 115.7 - Permission Granting via Popup Delay Misrepresentation
CVSS 8.8
CVE-2023-7282
MEDIUM
Google Chrome <113.0.5672.63 - SSRF
CVSS 4.3
CVE-2023-7281
MEDIUM
Google Chrome <119.0.6045.105 - XSS
CVSS 4.3
CVE-2023-7011
MEDIUM
Google Chrome <119.0.6045.105 - XSS
CVSS 6.5
CVE-2023-50938
MEDIUM
IBM PowerSC 1.3, 2.0, and 2.1 - Clickjacking
CVSS 6.5
CVE-2023-2941
MEDIUM
Google Chrome < 114.0.5735.90 - UI Spoofing via Malicious Extension
CVSS 4.3
CVE-2023-2938
MEDIUM
Google Chrome < 114.0.5735.90 - URL Spoofing via Picture In Picture
CVSS 4.3
CVE-2023-2937
MEDIUM
Google Chrome < 114.0.5735.90 - URL Spoofing via Picture In Picture
CVSS 4.3
CVE-2023-0700
MEDIUM
Google Chrome < 110.0.5481.77 - URL Spoofing via Omnibox Manipulation
CVSS 6.5
CVE-2023-0130
MEDIUM
Google Chrome < 109.0.5414.74 - URL Spoofing via Fullscreen API
CVSS 6.5
CVE-2022-45404
MEDIUM
Firefox ESR < 102.5, Thunderbird < 102.5, Firefox < 107 - SSRF
CVSS 6.5
CVE-2022-34479
MEDIUM
Firefox <102, Firefox ESR <91.11, Thunderbird <102, Thunderbird <91...
CVSS 6.5
CVE-2022-26383
MEDIUM
Firefox < 98.0, Firefox ESR < 91.7, and Thunderbird < 91.7 - Fullscreen Notification Bypass via Popup Resizing
CVSS 4.3
CVE-2022-22762
MEDIUM
Firefox < 97.0 - User Interface Misrepresentation via JavaScript Alert Overlay
CVSS 4.3
CVE-2022-20530
MEDIUM
Android 13 - Unauthenticated Information Disclosure via Misleading Permission String
CVSS 5.3
CVE-2022-38163
LOW
F-Secure SAFE Browser <19.0 - Spoof
CVSS 3.5
CVE-2022-3313
MEDIUM
Google Chrome < 106.0.5249.62 - Security UI Spoofing via Full Screen Mode
CVSS 6.5
CVE-2022-39258
HIGH
mailcow < 2022-09 - Open Redirect via Spoofed Swagger Authorize Link
CVSS 8.1
CVE-2022-32816
MEDIUM
iPadOS < 15.6 - User Interface Spoofing via Malicious Website Framing
CVSS 6.5
CVE-2022-2800
MEDIUM
SourceCodester Gym Management System - XSS
CVSS 4.3
CVE-2022-23646
MEDIUM
Next.js 10.0.0-12.0.9 - User Interface Misrepresentation via SVG Image Host Configuration
CVSS 5.9
Details
Vulnerabilities
343