CWE-356 · 32 records
Product UI does not Warn User of Unsafe Actions
CVEs in this class
32 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2018-16858Weaponized | It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute libreoffice · libreoffice · CWE-356 | Critical9.8 | — | 67.3% | Mar 25, 2019 |
36Monitor | CVE-2019-6737No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.bitdefender · safepay · CWE-356 | High8.8 | — | 3.8% | Jun 3, 2019 |
36Monitor | CVE-2019-6736No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.bitdefender · safepay · CWE-356 | High8.8 | — | 3.7% | Jun 3, 2019 |
36Monitor | CVE-2019-6738No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.bitdefender · safepay · CWE-356 | High8.8 | — | 3.7% | Jun 3, 2019 |
36Monitor | CVE-2019-13322No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0.mi · mi browser · CWE-356 | High8.8 | — | 2.6% | Feb 10, 2020 |
35Monitor | CVE-2022-39362No exploit | Metabase vulnerable to arbitrary SQL execution from queryhashmetabase · metabase · CWE-356 | High8.8 | — | 0.9% | Oct 26, 2022 |
35Monitor | CVE-2025-2450No exploit | NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerabilityni · vision builder ai · CWE-356 | High8.8 | — | 0.5% | Mar 18, 2025 |
32Monitor | CVE-2025-3909No exploit | JavaScript Execution via Spoofed PDF Attachment and file:/// Linkmozilla · thunderbird · CWE-356 | High8.1 | — | 0.4% | May 14, 2025 |
32Monitor | CVE-2025-3839No exploit | Epiphany: insecure external protocol invocation in epiphanyCWE-356 | High8.0 | — | 0.4% | Jan 23, 2026 |
32Monitor | CVE-2026-25805No exploit | Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.zed · zed · CWE-356 | High8.0 | — | 0.4% | Feb 10, 2026 |
31Monitor | CVE-2022-35873No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-356 | High7.8 | — | 0.7% | Jul 25, 2022 |
31Monitor | CVE-2022-36970No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000aveva · aveva edge · CWE-356 | High7.8 | — | 0.7% | Mar 29, 2023 |
31Monitor | CVE-2026-0777No exploit | Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerabilityxmind · xmind · CWE-356 | High7.8 | — | 0.3% | Feb 20, 2026 |
31Monitor | CVE-2025-14403No exploit | PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerabilitypdfsam · enhanced · CWE-356 | High7.8 | — | 0.3% | Dec 23, 2025 |
31Monitor | CVE-2025-14415No exploit | Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerabilitysodapdf · soda pdf · CWE-356 | High7.8 | — | 0.3% | Dec 23, 2025 |
31Monitor | CVE-2025-14414No exploit | Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerabilitysodapdf · soda pdf desktop · CWE-356 | High7.8 | — | 0.2% | Dec 23, 2025 |
31Monitor | CVE-2025-14417No exploit | pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerabilitypdfforge · pdf architect · CWE-356 | High7.8 | — | 0.2% | Dec 23, 2025 |
31Monitor | CVE-2025-14412No exploit | Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerabilitysodapdf · soda pdf · CWE-356 | High7.8 | — | 0.2% | Dec 23, 2025 |
31Monitor | CVE-2026-28593No exploit | In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI.google · android · CWE-356 | High7.8 | — | 0.1% | Sep 8, 2026 |
30Monitor | CVE-2025-58335No exploit | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28jetbrains · junie · CWE-356 | High7.5 | — | 0.2% | Aug 28, 2025 |
28Monitor | CVE-2025-14402No exploit | PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfsam · enhanced · CWE-356 | High7.0 | — | 0.3% | Dec 23, 2025 |
28Monitor | CVE-2025-14404No exploit | PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfsam · enhanced · CWE-356 | High7.0 | — | 0.3% | Dec 23, 2025 |
28Monitor | CVE-2025-14416No exploit | pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfforge · pdf architect · CWE-356 | High7.0 | — | 0.2% | Dec 23, 2025 |
28Monitor | CVE-2025-14418No exploit | pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfforge · pdf architect · CWE-356 | High7.0 | — | 0.2% | Dec 23, 2025 |
27Monitor | CVE-2025-31334No exploit | Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable filerarlab · winrar · CWE-356 | Medium6.8 | — | 1.2% | Apr 3, 2025 |
- CVE-2018-1685859Plan
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute
CriticalCVSS 9.8WeaponizedEPSS 67%libreoffice · libreofficeMar 25, 2019
- CVE-2019-673736Monitor
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.
HighCVSS 8.8No exploitEPSS 4%bitdefender · safepayJun 3, 2019
- CVE-2019-673636Monitor
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.
HighCVSS 8.8No exploitEPSS 4%bitdefender · safepayJun 3, 2019
- CVE-2019-673836Monitor
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.
HighCVSS 8.8No exploitEPSS 4%bitdefender · safepayJun 3, 2019
- CVE-2019-1332236Monitor
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0.
HighCVSS 8.8No exploitEPSS 3%mi · mi browserFeb 10, 2020
- CVE-2022-3936235Monitor
Metabase vulnerable to arbitrary SQL execution from queryhash
HighCVSS 8.8No exploitEPSS 1%metabase · metabaseOct 26, 2022
- CVE-2025-245035Monitor
NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%ni · vision builder aiMar 18, 2025
- CVE-2025-390932Monitor
JavaScript Execution via Spoofed PDF Attachment and file:/// Link
HighCVSS 8.1No exploitEPSS 0%mozilla · thunderbirdMay 14, 2025
- CVE-2025-383932Monitor
Epiphany: insecure external protocol invocation in epiphany
HighCVSS 8.0No exploitEPSS 0%Jan 23, 2026
- CVE-2026-2580532Monitor
Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.
HighCVSS 8.0No exploitEPSS 0%zed · zedFeb 10, 2026
- CVE-2022-3587331Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
HighCVSS 7.8No exploitEPSS 1%inductiveautomation · ignitionJul 25, 2022
- CVE-2022-3697031Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000
HighCVSS 7.8No exploitEPSS 1%aveva · aveva edgeMar 29, 2023
- CVE-2026-077731Monitor
Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%xmind · xmindFeb 20, 2026
- CVE-2025-1440331Monitor
PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%pdfsam · enhancedDec 23, 2025
- CVE-2025-1441531Monitor
Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%sodapdf · soda pdfDec 23, 2025
- CVE-2025-1441431Monitor
Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%sodapdf · soda pdf desktopDec 23, 2025
- CVE-2025-1441731Monitor
pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%pdfforge · pdf architectDec 23, 2025
- CVE-2025-1441231Monitor
Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%sodapdf · soda pdfDec 23, 2025
- CVE-2026-2859331Monitor
In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI.
HighCVSS 7.8No exploitEPSS 0%google · androidSep 8, 2026
- CVE-2025-5833530Monitor
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28
HighCVSS 7.5No exploitEPSS 0%jetbrains · junieAug 28, 2025
- CVE-2025-1440228Monitor
PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability
HighCVSS 7.0No exploitEPSS 0%pdfsam · enhancedDec 23, 2025
- CVE-2025-1440428Monitor
PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability
HighCVSS 7.0No exploitEPSS 0%pdfsam · enhancedDec 23, 2025
- CVE-2025-1441628Monitor
pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability
HighCVSS 7.0No exploitEPSS 0%pdfforge · pdf architectDec 23, 2025
- CVE-2025-1441828Monitor
pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability
HighCVSS 7.0No exploitEPSS 0%pdfforge · pdf architectDec 23, 2025
- CVE-2025-3133427Monitor
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file
MediumCVSS 6.8No exploitEPSS 1%rarlab · winrarApr 3, 2025