CWE-357 · 19 records
Insufficient UI Warning of Dangerous Operations
CVEs in this class
19 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2025-49582No exploit | XWiki's required right warnings for macros are incompletexwiki · xwiki · CWE-357 | High8.6 | — | 0.9% | Jun 13, 2025 |
34Monitor | CVE-2025-49585No exploit | XWiki does not require right warnings for XClass definitionsxwiki · xwiki · CWE-357 | High8.6 | — | 0.4% | Jun 13, 2025 |
33Monitor | CVE-2019-13521No exploit | A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlrockwellautomation · arena · CWE-357 | High7.8 | — | 5.6% | Jan 27, 2020 |
32Monitor | CVE-2025-33054No exploit | Remote Desktop Spoofing Vulnerabilitymicrosoft · windows 11 22h2 · CWE-357 | High8.1 | — | 0.9% | Jul 8, 2025 |
31Monitor | CVE-2021-22645No exploit | Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1luxion · keyshot · CWE-357 | High7.8 | — | 1.6% | Feb 23, 2021 |
31Monitor | CVE-2024-43505No exploit | Microsoft Office Visio Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-357 | High7.8 | — | 0.7% | Oct 8, 2024 |
28Monitor | CVE-2026-26151No exploit | Remote Desktop Spoofing Vulnerabilitymicrosoft · windows 10 1607 · CWE-357 | High7.1 | — | 0.8% | Apr 14, 2026 |
26Monitor | CVE-2022-41904No exploit | Element iOS is vulnerable due to missing decoration for events decrypted with untrusted Megolm sessionselement · element · CWE-357 | Medium6.5 | — | 0.4% | Nov 11, 2022 |
25Monitor | CVE-2025-49587No exploit | XWiki does not require right warnings for notification displayer objectsxwiki · xwiki · CWE-357 | Medium6.4 | — | 0.4% | Jun 13, 2025 |
21Monitor | CVE-2024-21387No exploit | Microsoft Edge for Android Spoofing Vulnerabilitymicrosoft · edge chromium · CWE-357 | Medium5.3 | — | 0.7% | Jan 25, 2024 |
21Monitor | CVE-2024-43580No exploit | Microsoft Edge (Chromium-based) Spoofing Vulnerabilitymicrosoft · edge chromium · CWE-357 | Medium5.4 | — | 0.4% | Oct 17, 2024 |
21Monitor | CVE-2024-30058No exploit | Microsoft Edge (Chromium-based) Spoofing Vulnerabilitymicrosoft · edge chromium · CWE-357 | Medium5.4 | — | 0.4% | Jun 13, 2024 |
18Monitor | CVE-2025-47967No exploit | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerabilitymicrosoft · edge · CWE-357 | Medium4.7 | — | 0.4% | Sep 16, 2025 |
18Monitor | CVE-2026-47782No exploit | Android App "RoboForm Password Manager" provided by Siber Systems, Inc.siber systems, inc. · android app "roboform password manager" · CWE-357 | Medium4.6 | — | 0.2% | May 20, 2026 |
17Monitor | CVE-2024-29057No exploit | Microsoft Edge (Chromium-based) Spoofing Vulnerabilitymicrosoft · edge · CWE-357 | Medium4.3 | — | 1.0% | Mar 22, 2024 |
17Monitor | CVE-2024-26188No exploit | Microsoft Edge (Chromium-based) Spoofing Vulnerabilitymicrosoft · edge · CWE-357 | Medium4.3 | — | 0.8% | Feb 23, 2024 |
17Monitor | CVE-2026-58597No exploit | Microsoft Edge (Chromium-based) Spoofing Vulnerabilitymicrosoft · edge chromium · CWE-357 | Medium4.3 | — | 0.7% | Jul 3, 2026 |
17Monitor | CVE-2024-49054No exploit | Microsoft Edge (Chromium-based) Spoofing Vulnerabilitymicrosoft · edge chromium · CWE-357 | Medium4.3 | — | 0.6% | Nov 22, 2024 |
10Monitor | CVE-2024-21336No exploit | Microsoft Edge (Chromium-based) Spoofing Vulnerabilitymicrosoft · edge chromium · CWE-357 | Low2.5 | — | 0.5% | Jan 26, 2024 |
- CVE-2025-4958234Monitor
XWiki's required right warnings for macros are incomplete
HighCVSS 8.6No exploitEPSS 1%xwiki · xwikiJun 13, 2025
- CVE-2025-4958534Monitor
XWiki does not require right warnings for XClass definitions
HighCVSS 8.6No exploitEPSS 0%xwiki · xwikiJun 13, 2025
- CVE-2019-1352133Monitor
A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earl
HighCVSS 7.8No exploitEPSS 6%rockwellautomation · arenaJan 27, 2020
- CVE-2025-3305432Monitor
Remote Desktop Spoofing Vulnerability
HighCVSS 8.1No exploitEPSS 1%microsoft · windows 11 22h2Jul 8, 2025
- CVE-2021-2264531Monitor
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1
HighCVSS 7.8No exploitEPSS 2%luxion · keyshotFeb 23, 2021
- CVE-2024-4350531Monitor
Microsoft Office Visio Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 1%microsoft · 365 appsOct 8, 2024
- CVE-2026-2615128Monitor
Remote Desktop Spoofing Vulnerability
HighCVSS 7.1No exploitEPSS 1%microsoft · windows 10 1607Apr 14, 2026
- CVE-2022-4190426Monitor
Element iOS is vulnerable due to missing decoration for events decrypted with untrusted Megolm sessions
MediumCVSS 6.5No exploitEPSS 0%element · elementNov 11, 2022
- CVE-2025-4958725Monitor
XWiki does not require right warnings for notification displayer objects
MediumCVSS 6.4No exploitEPSS 0%xwiki · xwikiJun 13, 2025
- CVE-2024-2138721Monitor
Microsoft Edge for Android Spoofing Vulnerability
MediumCVSS 5.3No exploitEPSS 1%microsoft · edge chromiumJan 25, 2024
- CVE-2024-4358021Monitor
Microsoft Edge (Chromium-based) Spoofing Vulnerability
MediumCVSS 5.4No exploitEPSS 0%microsoft · edge chromiumOct 17, 2024
- CVE-2024-3005821Monitor
Microsoft Edge (Chromium-based) Spoofing Vulnerability
MediumCVSS 5.4No exploitEPSS 0%microsoft · edge chromiumJun 13, 2024
- CVE-2025-4796718Monitor
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
MediumCVSS 4.7No exploitEPSS 0%microsoft · edgeSep 16, 2025
- CVE-2026-4778218Monitor
Android App "RoboForm Password Manager" provided by Siber Systems, Inc.
MediumCVSS 4.6No exploitEPSS 0%siber systems, inc. · android app "roboform password manager"May 20, 2026
- CVE-2024-2905717Monitor
Microsoft Edge (Chromium-based) Spoofing Vulnerability
MediumCVSS 4.3No exploitEPSS 1%microsoft · edgeMar 22, 2024
- CVE-2024-2618817Monitor
Microsoft Edge (Chromium-based) Spoofing Vulnerability
MediumCVSS 4.3No exploitEPSS 1%microsoft · edgeFeb 23, 2024
- CVE-2026-5859717Monitor
Microsoft Edge (Chromium-based) Spoofing Vulnerability
MediumCVSS 4.3No exploitEPSS 1%microsoft · edge chromiumJul 3, 2026
- CVE-2024-4905417Monitor
Microsoft Edge (Chromium-based) Spoofing Vulnerability
MediumCVSS 4.3No exploitEPSS 1%microsoft · edge chromiumNov 22, 2024
- CVE-2024-2133610Monitor
Microsoft Edge (Chromium-based) Spoofing Vulnerability
LowCVSS 2.5No exploitEPSS 1%microsoft · edge chromiumJan 26, 2024