CWE-451

User Interface (UI) Misrepresentation of Critical Information

Parent: CWE-684 - Incorrect Provision of Specified Functionality

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

230 vulnerabilities with CWE-451
CVE-2026-5905 MEDIUM
Google Chrome <147.0.7727.55 - Domain Spoofing
CVSS 6.5
CVE-2026-5898 MEDIUM
Google Chrome <147.0.7727.55 - UI Spoofing
CVSS 4.3
CVE-2026-5897 MEDIUM
Google Chrome <147.0.7727.55 - UI Spoofing
CVSS 4.3
CVE-2026-5895 MEDIUM
Google Chrome <147.0.7727.55 - Security UI Spoofing
CVSS 5.4
CVE-2026-5891 MEDIUM
Google Chrome <147.0.7727.55 - UI Spoofing
CVSS 4.3
CVE-2026-5882 MEDIUM
Google Chrome <147.0.7727.55 - UI Spoofing
CVSS 4.3
CVE-2026-5880 MEDIUM
Google Chrome <147.0.7727.55 - URL Spoofing
CVSS 4.3
CVE-2026-5878 MEDIUM
Google Chrome <147.0.7727.55 - UI Spoofing
CVSS 4.3
CVE-2026-32971 HIGH
OpenClaw < 2026.3.11 - Node-Host Approval UI Mismatch Allows Execution of Unintended Commands
CVSS 7.1
CVE-2026-3889 MEDIUM
Spoofing issue in Thunderbird
CVSS 6.5
CVE-2026-32318 HIGH
Cryptomator for IOS: Tampered vault configuration allows MITM attack on Hub API
CVSS 7.6
CVE-2026-32317 HIGH
Cryptomator for Android: Tampered vault configuration allows MITM attack on Hub API
CVSS 7.6
CVE-2026-32303 HIGH
Cryptomator: Tampered vault configuration allows MITM attack on Hub API
CVSS 7.6
CVE-2026-0385 MEDIUM
Microsoft Edge (Chromium-based) for Android - Spoofing
CVSS 5.0
CVE-2026-3942 MEDIUM
Google Chrome <146.0.7680.71 - UI Spoofing
CVSS 4.3
CVE-2026-3937 MEDIUM
Google Chrome Android <146.0.7680.71 - UI Spoofing
CVSS 6.5
CVE-2026-3935 MEDIUM
Google Chrome <146.0.7680.71 - UI Spoofing
CVSS 6.5
CVE-2026-3928 MEDIUM
Google Chrome <146.0.7680.71 - UI Spoofing
CVSS 4.3
CVE-2026-3927 MEDIUM
Google Chrome <146.0.7680.71 - UI Spoofing
CVSS 4.3
CVE-2026-3925 MEDIUM
Google Chrome Android <146.0.7680.71 - UI Spoofing
CVSS 4.3
CVE-2026-2919 MEDIUM
Focus for iOS <148.2 - Open Redirect
CVSS 4.3
CVE-2026-2634 CRITICAL
Firefox for iOS < 147.4 - Address Bar Spoofing via Desynchronization
CVSS 9.8
CVE-2026-26320 MEDIUM
OpenClaw macOS 2026.2.6-2026.2.13 - Command Injection
CVSS 6.5
CVE-2026-1658 MEDIUM
OpenText Directory Services 20.4.1-25.2 - Cache Poisoning
CVSS 5.3
CVE-2026-2032 MEDIUM
Firefox < 147.2.1 and Firefox for iOS >= 147.2.1 - Address Bar Spoofing via New Tab Page Loading Interruption
CVSS 4.3
Details
Vulnerabilities 230