CWE-451

User Interface (UI) Misrepresentation of Critical Information

Parent: CWE-684 - Incorrect Provision of Specified Functionality

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

340 vulnerabilities with CWE-451
CVE-2026-3937 MEDIUM
Google Chrome Android <146.0.7680.71 - UI Spoofing
CVSS 6.5
CVE-2026-3935 MEDIUM
Google Chrome <146.0.7680.71 - UI Spoofing
CVSS 6.5
CVE-2026-3928 MEDIUM
Google Chrome <146.0.7680.71 - UI Spoofing
CVSS 4.3
CVE-2026-3927 MEDIUM
Google Chrome <146.0.7680.71 - UI Spoofing
CVSS 4.3
CVE-2026-3925 MEDIUM
Google Chrome Android <146.0.7680.71 - UI Spoofing
CVSS 4.3
CVE-2026-2919 MEDIUM
Focus for iOS <148.2 - Open Redirect
CVSS 4.3
CVE-2026-2634 CRITICAL
Firefox for iOS < 147.4 - Address Bar Spoofing via Desynchronization
CVSS 9.8
CVE-2026-26320 MEDIUM
OpenClaw macOS 2026.2.6-2026.2.13 - Command Injection
CVSS 6.5
CVE-2026-1658 MEDIUM
OpenText Directory Services 20.4.1-25.2 - Cache Poisoning
CVSS 5.3
CVE-2026-2032 MEDIUM
Firefox < 147.2.1 and Firefox for iOS >= 147.2.1 - Address Bar Spoofing via New Tab Page Loading Interruption
CVSS 4.3
CVE-2026-2323 MEDIUM
Google Chrome < 145.0.7632.45 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-2322 MEDIUM
Google Chrome < 145.0.7632.45 - UI Spoofing via File Input
CVSS 5.4
CVE-2026-2320 MEDIUM
Google Chrome < 145.0.7632.45 - UI Spoofing via File Input
CVSS 6.5
CVE-2026-2318 MEDIUM
Google Chrome < 145.0.7632.45 - UI Spoofing via PictureInPicture Implementation
CVSS 6.5
CVE-2026-2316 MEDIUM
Google Chrome < 145.0.7632.45 - UI Spoofing via Crafted HTML Page
CVSS 6.5
CVE-2026-21527 MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 6.5
CVE-2026-0391 MEDIUM
Microsoft Edge for Android - Info Disclosure
CVSS 6.5
CVE-2026-20732 LOW
F5 BIG-IP 16.1.0-16.1.6 - User Interface Misrepresentation of Critical Information
CVSS 3.1
CVE-2026-0907 CRITICAL
Google Chrome < 144.0.7559.59 - Security UI Spoofing via Split View
CVSS 9.8
CVE-2026-0906 CRITICAL
Google Chrome < 144.0.7559.59 - User Interface Misrepresentation via Omnibox Spoofing
CVSS 9.8
CVE-2026-0904 MEDIUM
Google Chrome <144.0.7559.59 - CSRF
CVSS 5.4
CVE-2026-0901 MEDIUM
Google Chrome < 144.0.7559.59 - UI Spoofing via Crafted HTML Page
CVSS 5.4
CVE-2025-46311 HIGH
Apple Ios And iPadOS - User Interface (UI) Misrepresentation of Critical Information
CVSS 7.5
CVE-2025-31951 HIGH
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
CVSS 8.8
CVE-2025-68277 MEDIUM
OpenEMR < 7.0.4 - User Interface Misrepresentation via Secure Messaging Link Handling
CVSS 5.0
Details
Vulnerabilities 340