VulnSea

CWE-451

CVEs classified under CWE-451, newest first.

60 CVEsRSS

CVE-2026-18622Medium· 4.7
1mo ago

Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication

Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the…

▾ Sunlitfoxit · pdf_editorEPSS 0.12%via NVD
CVE-2026-17849Medium· 4.3
1mo ago

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via malicious network traffic

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via malicious network traffic. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.23%via NVD
CVE-2026-35371Low· 3.3
2mo ago

id: pretty-print uses effective GID instead of effective UID for name lookup

id: pretty-print uses effective GID instead of effective UID for name lookup

▾ Sunlituu_id · uu_idEPSS 0.14%via GHSA
CVE-2026-45488Medium· 5.4
2mo ago

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.36%via NVD
CVE-2026-48760Medium
3mo ago

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

▾ Sunlitsymfony · symfony/html-sanitizerEPSS 0.34%via GHSA
CVE-2026-45650Medium· 4.3
3mo ago

Microsoft Bing Search Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Bing Search for AndroidEPSS 0.70%via CVEORG
CVE-2026-0096High· 7.8
3mo ago

In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI

In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges…

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0094High· 7.8
3mo ago

In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI

In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional ex…

▾ Twilightgoogle · androidEPSS 0.06%via NVD
CVE-2026-0093High· 7.8
3mo ago

In multiple locations, there is a possible misleading UI due to obfuscation

In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0088High· 7.8
3mo ago

In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI

In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges nee…

▾ Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2019-25718High· 8.4
3mo ago

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kio…

▾ Twilightdraeger · infinity_explorer_c700_firmwareEPSS 0.12%via NVD
CVE-2026-8964High· 7.5
4mo ago

Spoofing issue in the Popup Blocker component

Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

▾ Twilightmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-3861Medium· 6.5
5mo ago

LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, pote…

LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, pote…

▾ Sunlitlinecorp · lineEPSS 0.34%via NVD
CVE-2026-33119Medium· 5.4
5mo ago

Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge for AndroidEPSS 0.41%via CVEORG
CVE-2026-33118Medium· 4.3
5mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.70%via CVEORG
CVE-2026-5906Medium· 4.3
5mo ago

Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page

Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-5905Medium· 6.5
5mo ago

Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page

Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.29%via NVD
CVE-2026-5898Medium· 4.3
5mo ago

Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page

Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.26%via NVD
CVE-2026-5897Medium· 4.3
5mo ago

Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page

Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.23%via NVD
CVE-2026-5895Medium· 5.4
5mo ago

Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name

Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-5891Medium· 4.3
5mo ago

Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page

Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.26%via NVD
CVE-2026-5882Medium· 4.3
5mo ago

Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page

Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-5880Medium· 4.3
5mo ago

Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page

Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium se…

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-5878Medium· 4.3
5mo ago

Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page

Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-32971High· 7.1
6mo ago

OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv

OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped …

▾ Twilightopenclaw · openclawEPSS 0.38%via NVD
CVE-2025-62223Medium· 4.3
9mo ago

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · edge_chromiumEPSS 0.43%via NVD
CVE-2024-52270High· 8.2PoC
1y ago

PDF Document Spoofing in DropBox Sign(HelloSign)

User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrom…

▾ MidnightDropBox(HelloSign) · DropBox SignEPSS 0.19%via CVEORG
CVE-2024-38093Medium· 4.3
2y ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

▾ Sunlitmicrosoft · edgeEPSS 0.50%via NVD
CVE-2024-38082Medium· 4.7
2y ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

▾ Sunlitmicrosoft · edgeEPSS 0.50%via NVD
CVE-2024-38313Medium· 4.3
2y ago

In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.

In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.

▾ Sunlitmozilla · firefox_mobileEPSS 0.24%via NVD
CWE-451 vulnerabilities (CVEs) — page 2 · VulnSea