CWE-451 · 380 kayıt
User Interface (UI) Misrepresentation of Critical Information
Bu sınıftaki CVE’ler
380 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
85Hemen | CVE-2024-38112Silahlaştırılmış | Windows MSHTML Platform Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-451 | Yüksek7,5 | KEV | %84,2 | 9 Tem 2024 |
81Hemen | CVE-2024-43461Silahlaştırılmış | Windows MSHTML Platform Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-451 | Yüksek8,8 | KEV | %54,5 | 10 Eyl 2024 |
42Planlayın | CVE-2026-0907İstismar yok | Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted Hgoogle · chrome · CWE-451 | Kritik9,8 | — | %8,6 | 20 Oca 2026 |
39İzleyin | CVE-2025-9491Kavram kanıtı | Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerabilitymicrosoft · windows 11 23h2 · CWE-451 | Orta4,6 | — | %68,9 | 26 Ağu 2025 |
39İzleyin | CVE-2026-2634İstismar yok | Spoofed web content presented under trusted domains using scripted navigation on Firefox iOSmozilla · firefox · CWE-451 | Kritik9,8 | — | %0,5 | 24 Şub 2026 |
39İzleyin | CVE-2025-8043İstismar yok | Incorrect URL truncationmozilla · firefox · CWE-451 | Kritik9,8 | — | %0,4 | 22 Tem 2025 |
39İzleyin | CVE-2026-0906İstismar yok | Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URgoogle · chrome · CWE-451 | Kritik9,8 | — | %0,3 | 20 Oca 2026 |
35İzleyin | CVE-2021-41598İstismar yok | UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to usergithub · enterprise server · CWE-451 | Yüksek8,8 | — | %1,2 | 25 Oca 2022 |
35İzleyin | CVE-2021-22866İstismar yok | UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resourcesgithub · enterprise server · CWE-451 | Yüksek8,8 | — | %1,0 | 14 May 2021 |
35İzleyin | CVE-2024-0750İstismar yok | A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions.mozilla · firefox · CWE-451 | Yüksek8,8 | — | %0,8 | 23 Oca 2024 |
35İzleyin | CVE-2020-9236İstismar yok | There is an improper interface design vulnerability in Huawei product.huawei · fusioncompute · CWE-451 | Yüksek8,8 | — | %0,4 | 27 Ara 2024 |
35İzleyin | CVE-2026-11175İstismar yok | Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a google · chrome · CWE-451 | Yüksek8,8 | — | %0,2 | 4 Haz 2026 |
35İzleyin | CVE-2026-11172İstismar yok | Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing google · chrome · CWE-451 | Yüksek8,8 | — | %0,2 | 4 Haz 2026 |
34İzleyin | CVE-2026-53829İstismar yok | OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Displayopenclaw · openclaw · CWE-451 | Yüksek8,5 | — | %0,4 | 12 Haz 2026 |
34İzleyin | CVE-2019-25718İstismar yok | Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypassdraeger · infinity explorer c700 firmware · CWE-451 | Yüksek8,6 | — | %0,1 | 1 Haz 2026 |
33İzleyin | CVE-2024-49040İstismar yok | Microsoft Exchange Server Spoofing Vulnerabilitymicrosoft · exchange server · CWE-451 | Yüksek7,5 | — | %8,5 | 12 Kas 2024 |
32İzleyin | CVE-2024-52276İstismar yok | PDF Document Spoofing in DocuSigndocusign · docusign · CWE-451 | Yüksek8,2 | — | %0,4 | 4 Ara 2024 |
32İzleyin | CVE-2026-79011İstismar yok | UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass sygoogle · chrome · CWE-451 | Yüksek8,1 | — | %0,3 | 25 Ağu 2026 |
32İzleyin | CVE-2024-52269İstismar yok | AI Assistant PDF Document Spoofing in DocuSigndocusign · docusign · CWE-451 | Yüksek8,2 | — | %0,3 | 4 Ara 2024 |
32İzleyin | CVE-2025-11720İstismar yok | Spoofing risk in Android custom tabsmozilla · firefox · CWE-451 | Yüksek8,1 | — | %0,3 | 14 Eki 2025 |
32İzleyin | CVE-2024-52271İstismar yok | PDF Document Spoofing in Documensodocumenso · documenso · CWE-451 | Yüksek8,2 | — | %0,2 | 5 Ara 2024 |
32İzleyin | CVE-2024-52277İstismar yok | PDF Document Spoofing in DocuSealdocuseal · docuseal · CWE-451 | Yüksek8,2 | — | %0,2 | 4 Ara 2024 |
32İzleyin | CVE-2024-52270İstismar yok | PDF Document Spoofing in DropBox Sign(HelloSign)dropbox(hellosign) · dropbox sign · CWE-451 | Yüksek8,2 | — | %0,2 | 5 Ara 2024 |
31İzleyin | CVE-2024-38197İstismar yok | Microsoft Teams for iOS Spoofing Vulnerabilitymicrosoft · teams · CWE-451 | Orta6,5 | — | %16,1 | 13 Ağu 2024 |
31İzleyin | CVE-2022-23646İstismar yok | Improper CSP in Image Optimization API for Next.jsvercel · next.js · CWE-451 | Yüksek7,5 | — | %1,8 | 17 Şub 2022 |
- CVE-2024-3811285Hemen
Windows MSHTML Platform Spoofing Vulnerability
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %84microsoft · windows 10 15079 Tem 2024
- CVE-2024-4346181Hemen
Windows MSHTML Platform Spoofing Vulnerability
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %54microsoft · windows 10 150710 Eyl 2024
- CVE-2026-090742Planlayın
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted H
KritikCVSS 9,8İstismar yokEPSS %9google · chrome20 Oca 2026
- CVE-2025-949139İzleyin
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability
OrtaCVSS 4,6Kavram kanıtıEPSS %69microsoft · windows 11 23h226 Ağu 2025
- CVE-2026-263439İzleyin
Spoofed web content presented under trusted domains using scripted navigation on Firefox iOS
KritikCVSS 9,8İstismar yokEPSS %0mozilla · firefox24 Şub 2026
- CVE-2025-804339İzleyin
Incorrect URL truncation
KritikCVSS 9,8İstismar yokEPSS %0mozilla · firefox22 Tem 2025
- CVE-2026-090639İzleyin
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (UR
KritikCVSS 9,8İstismar yokEPSS %0google · chrome20 Oca 2026
- CVE-2021-4159835İzleyin
UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user
YüksekCVSS 8,8İstismar yokEPSS %1github · enterprise server25 Oca 2022
- CVE-2021-2286635İzleyin
UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resources
YüksekCVSS 8,8İstismar yokEPSS %1github · enterprise server14 May 2021
- CVE-2024-075035İzleyin
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions.
YüksekCVSS 8,8İstismar yokEPSS %1mozilla · firefox23 Oca 2024
- CVE-2020-923635İzleyin
There is an improper interface design vulnerability in Huawei product.
YüksekCVSS 8,8İstismar yokEPSS %0huawei · fusioncompute27 Ara 2024
- CVE-2026-1117535İzleyin
Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a
YüksekCVSS 8,8İstismar yokEPSS %0google · chrome4 Haz 2026
- CVE-2026-1117235İzleyin
Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing
YüksekCVSS 8,8İstismar yokEPSS %0google · chrome4 Haz 2026
- CVE-2026-5382934İzleyin
OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display
YüksekCVSS 8,5İstismar yokEPSS %0openclaw · openclaw12 Haz 2026
- CVE-2019-2571834İzleyin
Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass
YüksekCVSS 8,6İstismar yokEPSS %0draeger · infinity explorer c700 firmware1 Haz 2026
- CVE-2024-4904033İzleyin
Microsoft Exchange Server Spoofing Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %8microsoft · exchange server12 Kas 2024
- CVE-2024-5227632İzleyin
PDF Document Spoofing in DocuSign
YüksekCVSS 8,2İstismar yokEPSS %0docusign · docusign4 Ara 2024
- CVE-2026-7901132İzleyin
UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass sy
YüksekCVSS 8,1İstismar yokEPSS %0google · chrome25 Ağu 2026
- CVE-2024-5226932İzleyin
AI Assistant PDF Document Spoofing in DocuSign
YüksekCVSS 8,2İstismar yokEPSS %0docusign · docusign4 Ara 2024
- CVE-2025-1172032İzleyin
Spoofing risk in Android custom tabs
YüksekCVSS 8,1İstismar yokEPSS %0mozilla · firefox14 Eki 2025
- CVE-2024-5227132İzleyin
PDF Document Spoofing in Documenso
YüksekCVSS 8,2İstismar yokEPSS %0documenso · documenso5 Ara 2024
- CVE-2024-5227732İzleyin
PDF Document Spoofing in DocuSeal
YüksekCVSS 8,2İstismar yokEPSS %0docuseal · docuseal4 Ara 2024
- CVE-2024-5227032İzleyin
PDF Document Spoofing in DropBox Sign(HelloSign)
YüksekCVSS 8,2İstismar yokEPSS %0dropbox(hellosign) · dropbox sign5 Ara 2024
- CVE-2024-3819731İzleyin
Microsoft Teams for iOS Spoofing Vulnerability
OrtaCVSS 6,5İstismar yokEPSS %16microsoft · teams13 Ağu 2024
- CVE-2022-2364631İzleyin
Improper CSP in Image Optimization API for Next.js
YüksekCVSS 7,5İstismar yokEPSS %2vercel · next.js17 Şub 2022