CWE-451

User Interface (UI) Misrepresentation of Critical Information

Parent: CWE-684 - Incorrect Provision of Specified Functionality

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

182 vulnerabilities with CWE-451
CVE-2025-46287 MEDIUM
Apple watchOS <26.2 - Info Disclosure
CVSS 6.5
CVE-2025-64667 MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 5.3
CVE-2025-62223 MEDIUM
Microsoft Edge for iOS - Info Disclosure
CVSS 4.3
CVE-2025-31266 MEDIUM
Safari <18.5 - Spoofing
CVSS 4.3
CVE-2025-13082 MEDIUM
Drupal Drupal core <11.2.8 - Content Spoofing
CVSS 4.3
CVE-2025-13107 MEDIUM
Google Chrome <140.0.7339.80 - XSS
CVSS 4.3
CVE-2025-13102 MEDIUM
Google Chrome <134.0.6998.35 - XSS
CVSS 4.3
CVE-2025-12729 MEDIUM
Google Chrome <142.0.7444.137 - XSS
CVSS 4.2
CVE-2025-12728 MEDIUM
Google Chrome <142.0.7444.137 - XSS
CVSS 4.2
CVE-2025-12446 MEDIUM
Google Chrome <142.0.7444.59 - CSRF
CVSS 4.2
CVE-2025-12435 MEDIUM
Google Chrome < 142.0.7444.59 - Improper Authorization
CVSS 5.4
CVE-2025-12911 MEDIUM
Google Chrome <140.0.7339.80 - XSS
CVSS 4.3
CVE-2025-11213 MEDIUM
Google Chrome <141.0.7390.54 - SSRF
CVSS 6.3
CVE-2025-11212 MEDIUM
Google Chrome <141.0.7390.54 - SSRF
CVSS 6.3
CVE-2025-11208 MEDIUM
Google Chrome <141.0.7390.54 - XSS
CVSS 6.3
CVE-2025-11720 HIGH
Firefox <144 - Info Disclosure
CVSS 8.1
CVE-2025-11718 MEDIUM
Firefox < 144 - Info Disclosure
CVSS 6.5
CVE-2025-10290 MEDIUM
Focus iOS <143.0 - CSRF
CVSS 6.5
CVE-2025-43327 MEDIUM
Safari <26 - CSRF
CVSS 6.5
CVE-2025-9867 MEDIUM
Google Chrome <140.0.7339.80 - XSS
CVSS 5.4
CVE-2025-9865 MEDIUM
Google Chrome <140.0.7339.80 - SSRF
CVSS 5.4
CVE-2025-9491 HIGH
Microsoft Windows - RCE
CVSS 7.8
CVE-2025-9186 MEDIUM
Firefox <142 - SSRF
CVSS 6.5
CVE-2025-9183 MEDIUM
Firefox < 142 - SSRF
CVSS 6.5
CVE-2025-8364 MEDIUM
Firefox < 141 - SSRF
CVSS 4.3
Details
Vulnerabilities 182