Skip to content
Noroxi

CWE-356 · 32 records

Product UI does not Warn User of Unsafe Actions

CVEs in this class

32 records

  • It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute

    CriticalCVSS 9.8WeaponizedEPSS 67%

    libreoffice · libreofficeMar 25, 2019

  • CVE-2019-6737
    36Monitor

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.

    HighCVSS 8.8No exploitEPSS 4%

    bitdefender · safepayJun 3, 2019

  • CVE-2019-6736
    36Monitor

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.

    HighCVSS 8.8No exploitEPSS 4%

    bitdefender · safepayJun 3, 2019

  • CVE-2019-6738
    36Monitor

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.

    HighCVSS 8.8No exploitEPSS 4%

    bitdefender · safepayJun 3, 2019

  • This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0.

    HighCVSS 8.8No exploitEPSS 3%

    mi · mi browserFeb 10, 2020

  • Metabase vulnerable to arbitrary SQL execution from queryhash

    HighCVSS 8.8No exploitEPSS 1%

    metabase · metabaseOct 26, 2022

  • CVE-2025-2450
    35Monitor

    NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    ni · vision builder aiMar 18, 2025

  • CVE-2025-3909
    32Monitor

    JavaScript Execution via Spoofed PDF Attachment and file:/// Link

    HighCVSS 8.1No exploitEPSS 0%

    mozilla · thunderbirdMay 14, 2025

  • CVE-2025-3839
    32Monitor

    Epiphany: insecure external protocol invocation in epiphany

    HighCVSS 8.0No exploitEPSS 0%

    Jan 23, 2026

  • Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.

    HighCVSS 8.0No exploitEPSS 0%

    zed · zedFeb 10, 2026

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202

    HighCVSS 7.8No exploitEPSS 1%

    inductiveautomation · ignitionJul 25, 2022

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000

    HighCVSS 7.8No exploitEPSS 1%

    aveva · aveva edgeMar 29, 2023

  • CVE-2026-0777
    31Monitor

    Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    xmind · xmindFeb 20, 2026

  • PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    pdfsam · enhancedDec 23, 2025

  • Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    sodapdf · soda pdfDec 23, 2025

  • Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    sodapdf · soda pdf desktopDec 23, 2025

  • pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    pdfforge · pdf architectDec 23, 2025

  • Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    sodapdf · soda pdfDec 23, 2025

  • In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI.

    HighCVSS 7.8No exploitEPSS 0%

    google · androidSep 8, 2026

  • In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28

    HighCVSS 7.5No exploitEPSS 0%

    jetbrains · junieAug 28, 2025

  • PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability

    HighCVSS 7.0No exploitEPSS 0%

    pdfsam · enhancedDec 23, 2025

  • PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability

    HighCVSS 7.0No exploitEPSS 0%

    pdfsam · enhancedDec 23, 2025

  • pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability

    HighCVSS 7.0No exploitEPSS 0%

    pdfforge · pdf architectDec 23, 2025

  • pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability

    HighCVSS 7.0No exploitEPSS 0%

    pdfforge · pdf architectDec 23, 2025

  • Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file

    MediumCVSS 6.8No exploitEPSS 1%

    rarlab · winrarApr 3, 2025

All vulnerability classes