VulnSea

CWE-1021

CVEs classified under CWE-1021, newest first.

16 CVEsRSS

CVE-2026-86911Medium· 5.5
1w ago

This issue was addressed with improved state management

This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to bypass clickjacking protections for secure prompts.

Sunlitapple · macosEPSS 0.13%via NVD
CVE-2026-43688High· 7.8
1w ago

A memory corruption issue was addressed with improved input validation

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing a maliciously crafted file may lead to unexpected app termination.

Twilightapple · ipadosEPSS 0.16%via NVD
CVE-2026-87995High· 8.7PoC
1w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-…

Midnightopenwebui · open_webuiEPSS 0.23%via NVD
CVE-2026-87655Medium· 5.4
1w ago

Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page

Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.18%via NVD
CVE-2026-87486Medium· 4.0
1w ago

Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app

Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.12%via NVD
CVE-2026-87538Medium· 4.2⚖ disputed
1w ago

Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page

Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: …

Sunlitgoogle · chromeEPSS 0.20%via NVD
CVE-2026-28656High· 7.3
1w ago

In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack

In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is …

Twilightgoogle · androidEPSS 0.07%via NVD
GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

Twilightgeolens · geolensvia GHSA
CVE-2026-70608High· 7.2
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger s…

Twilightelectron · electronEPSS 0.32%via NVD
CVE-2026-70600Low· 3.1
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside th…

Sunlitelectron · electronEPSS 0.18%via NVD
CVE-2026-70486High· 8.2
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files s…

Twilightopenwebui · open_webuiEPSS 0.31%via NVD
CVE-2026-58595High· 8.1
2mo ago

Microsoft Bing App for IOS Spoofing Vulnerability

Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.

TwilightMicrosoft · Microsoft Bing Search for iOSEPSS 0.69%via CVEORG
CVE-2026-44727Medium· 5.4
3mo ago

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

Sunlitjupyter-server · jupyter-serverEPSS 0.44%via OSV
CVE-2026-47723High
3mo ago

nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)

nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)

Twilightjuev · github.com/juev/nebula-meshEPSS 0.53%via GHSA
CVE-2024-7523High· 8.1
2y ago

A select option could partially obscure security prompts

A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.

Twilightmozilla · firefox_mobileEPSS 0.27%via NVD
CVE-2021-41657Medium· 6.1
4y ago

SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.

SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.

Sunlitsmartbear · collaboratorEPSS 0.78%via NVD
CWE-1021 vulnerabilities (CVEs) · VulnSea