CWE-451
User Interface (UI) Misrepresentation of Critical Information
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
230 vulnerabilities with CWE-451
CVE-2024-43461
HIGH
KEV
Windows MSHTML Platform - Spoofing
CVSS 8.8
CVE-2024-38197
MEDIUM
Microsoft Teams for iOS < 6.19.2 - User Interface Spoofing
CVSS 6.5
CVE-2024-6999
MEDIUM
Google Chrome < 127.0.6533.72 - UI Spoofing via FedCM Implementation
CVSS 4.3
CVE-2024-7529
MEDIUM
Firefox < 129 and Firefox ESR < 115.14 - UI Misrepresentation via Date Picker Overlay
CVSS 6.5
CVE-2024-6595
LOW
GitLab CE/EE <16.11.6/<17.0.4/<17.1.2 - Info Disclosure
CVSS 3.0
CVE-2024-38112
HIGH
KEV
Windows MSHTML Platform - Spoofing
CVSS 7.5
CVE-2024-6610
MEDIUM
Firefox and Thunderbird < 128.0 - UI Misrepresentation via Form Validation Popup Escape Key Capture
CVSS 4.3
CVE-2024-38093
MEDIUM
Microsoft Edge < 126.0.2592.68 - Spoofing via UI Misrepresentation
CVSS 4.3
CVE-2024-38082
MEDIUM
Microsoft Edge < 126.0.2592.68 - User Interface Spoofing
CVSS 4.7
CVE-2024-38313
MEDIUM
Firefox for iOS < 127 - Info Disclosure
CVSS 4.3
CVE-2024-5698
MEDIUM
Firefox < 127 - User Interface Misrepresentation via Fullscreen Data-List Overlay
CVSS 6.1
CVE-2024-4950
MEDIUM
Google Chrome < 125.0.6422.60 - UI Spoofing via Crafted HTML Page
CVSS 6.5
CVE-2024-30055
MEDIUM
Microsoft Edge Chromium < 124.0.2478.97 - Spoofing
CVSS 5.4
CVE-2024-23708
HIGH
NotificationManagerService - Privilege Escalation
CVSS 7.8
CVE-2024-2631
MEDIUM
Google Chrome < 123.0.6312.58 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2024-0805
MEDIUM
Google Chrome <121.0.6167.85 - CSRF
CVSS 4.3
CVE-2024-0750
HIGH
Firefox < 122.0, Firefox ESR < 115.7, Thunderbird < 115.7 - Permission Granting via Popup Delay Misrepresentation
CVSS 8.8
CVE-2023-7282
MEDIUM
Google Chrome <113.0.5672.63 - SSRF
CVSS 4.3
CVE-2023-7281
MEDIUM
Google Chrome <119.0.6045.105 - XSS
CVSS 4.3
CVE-2023-7011
MEDIUM
Google Chrome <119.0.6045.105 - XSS
CVSS 6.5
CVE-2023-50938
MEDIUM
IBM PowerSC 1.3, 2.0, and 2.1 - Clickjacking
CVSS 6.5
CVE-2023-2941
MEDIUM
Google Chrome < 114.0.5735.90 - UI Spoofing via Malicious Extension
CVSS 4.3
CVE-2023-2938
MEDIUM
Google Chrome < 114.0.5735.90 - URL Spoofing via Picture In Picture
CVSS 4.3
CVE-2023-2937
MEDIUM
Google Chrome < 114.0.5735.90 - URL Spoofing via Picture In Picture
CVSS 4.3
CVE-2023-0700
MEDIUM
Google Chrome < 110.0.5481.77 - URL Spoofing via Omnibox Manipulation
CVSS 6.5
Details
Vulnerabilities
230