CWE-451

User Interface (UI) Misrepresentation of Critical Information

Parent: CWE-684 - Incorrect Provision of Specified Functionality

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

230 vulnerabilities with CWE-451
CVE-2026-2323 MEDIUM
Google Chrome < 145.0.7632.45 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-2322 MEDIUM
Google Chrome < 145.0.7632.45 - UI Spoofing via File Input
CVSS 5.4
CVE-2026-2320 MEDIUM
Google Chrome < 145.0.7632.45 - UI Spoofing via File Input
CVSS 6.5
CVE-2026-2318 MEDIUM
Google Chrome < 145.0.7632.45 - UI Spoofing via PictureInPicture Implementation
CVSS 6.5
CVE-2026-2316 MEDIUM
Google Chrome < 145.0.7632.45 - UI Spoofing via Crafted HTML Page
CVSS 6.5
CVE-2026-21527 MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 6.5
CVE-2026-0391 MEDIUM
Microsoft Edge for Android - Info Disclosure
CVSS 6.5
CVE-2026-20732 LOW
F5 BIG-IP 16.1.0-16.1.6 - User Interface Misrepresentation of Critical Information
CVSS 3.1
CVE-2026-0907 CRITICAL
Google Chrome < 144.0.7559.59 - Security UI Spoofing via Split View
CVSS 9.8
CVE-2026-0906 CRITICAL
Google Chrome < 144.0.7559.59 - User Interface Misrepresentation via Omnibox Spoofing
CVSS 9.8
CVE-2026-0904 MEDIUM
Google Chrome <144.0.7559.59 - CSRF
CVSS 5.4
CVE-2026-0901 MEDIUM
Google Chrome < 144.0.7559.59 - UI Spoofing via Crafted HTML Page
CVSS 5.4
CVE-2025-46311 HIGH
Apple Ios And iPadOS - User Interface (UI) Misrepresentation of Critical Information
CVSS 7.5
CVE-2025-31951 HIGH
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
CVSS 8.8
CVE-2025-68277 MEDIUM
OpenEMR < 7.0.4 - User Interface Misrepresentation via Secure Messaging Link Handling
CVSS 5.0
CVE-2025-62224 MEDIUM
Microsoft Edge for Android - Spoofing
CVSS 5.5
CVE-2025-65046 LOW
Microsoft Edge Chromium < 143.0.3650.88 - Spoofing
CVSS 3.1
CVE-2025-14744 MEDIUM
Firefox for iOS <144.0 - Info Disclosure
CVSS 6.5
CVE-2025-14023 LOW
LINE < 15.19.0 - User Interface Spoofing via Navigation State Inconsistency
CVSS 3.1
CVE-2025-14021 MEDIUM
LINE < 14.14.0 - Address Bar Spoofing via In-App Browser
CVSS 4.3
CVE-2025-14020 MEDIUM
LINE client for Android <14.20 - CSRF
CVSS 5.4
CVE-2025-14019 LOW
LINE client for Android <15.5 - Info Disclosure
CVSS 3.4
CVE-2025-46287 MEDIUM
Apple watchOS <26.2 - Info Disclosure
CVSS 6.5
CVE-2025-64667 MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 5.3
CVE-2025-62223 MEDIUM
Microsoft Edge for iOS - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 230