CWE-451 · 380 records
User Interface (UI) Misrepresentation of Critical Information
CVEs in this class
380 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
85Now | CVE-2024-38112Weaponized | Windows MSHTML Platform Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-451 | High7.5 | KEV | 84.2% | Jul 9, 2024 |
81Now | CVE-2024-43461Weaponized | Windows MSHTML Platform Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-451 | High8.8 | KEV | 54.5% | Sep 10, 2024 |
42Plan | CVE-2026-0907No exploit | Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted Hgoogle · chrome · CWE-451 | Critical9.8 | — | 8.6% | Jan 20, 2026 |
39Monitor | CVE-2025-9491Proof of concept | Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerabilitymicrosoft · windows 11 23h2 · CWE-451 | Medium4.6 | — | 68.9% | Aug 26, 2025 |
39Monitor | CVE-2026-2634No exploit | Spoofed web content presented under trusted domains using scripted navigation on Firefox iOSmozilla · firefox · CWE-451 | Critical9.8 | — | 0.5% | Feb 24, 2026 |
39Monitor | CVE-2025-8043No exploit | Incorrect URL truncationmozilla · firefox · CWE-451 | Critical9.8 | — | 0.4% | Jul 22, 2025 |
39Monitor | CVE-2026-0906No exploit | Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URgoogle · chrome · CWE-451 | Critical9.8 | — | 0.3% | Jan 20, 2026 |
35Monitor | CVE-2021-41598No exploit | UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to usergithub · enterprise server · CWE-451 | High8.8 | — | 1.2% | Jan 25, 2022 |
35Monitor | CVE-2021-22866No exploit | UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resourcesgithub · enterprise server · CWE-451 | High8.8 | — | 1.0% | May 14, 2021 |
35Monitor | CVE-2024-0750No exploit | A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions.mozilla · firefox · CWE-451 | High8.8 | — | 0.8% | Jan 23, 2024 |
35Monitor | CVE-2020-9236No exploit | There is an improper interface design vulnerability in Huawei product.huawei · fusioncompute · CWE-451 | High8.8 | — | 0.4% | Dec 27, 2024 |
35Monitor | CVE-2026-11175No exploit | Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a google · chrome · CWE-451 | High8.8 | — | 0.2% | Jun 4, 2026 |
35Monitor | CVE-2026-11172No exploit | Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing google · chrome · CWE-451 | High8.8 | — | 0.2% | Jun 4, 2026 |
34Monitor | CVE-2026-53829No exploit | OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Displayopenclaw · openclaw · CWE-451 | High8.5 | — | 0.4% | Jun 12, 2026 |
34Monitor | CVE-2019-25718No exploit | Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypassdraeger · infinity explorer c700 firmware · CWE-451 | High8.6 | — | 0.1% | Jun 1, 2026 |
33Monitor | CVE-2024-49040No exploit | Microsoft Exchange Server Spoofing Vulnerabilitymicrosoft · exchange server · CWE-451 | High7.5 | — | 8.5% | Nov 12, 2024 |
32Monitor | CVE-2024-52276No exploit | PDF Document Spoofing in DocuSigndocusign · docusign · CWE-451 | High8.2 | — | 0.4% | Dec 4, 2024 |
32Monitor | CVE-2026-79011No exploit | UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass sygoogle · chrome · CWE-451 | High8.1 | — | 0.3% | Aug 25, 2026 |
32Monitor | CVE-2024-52269No exploit | AI Assistant PDF Document Spoofing in DocuSigndocusign · docusign · CWE-451 | High8.2 | — | 0.3% | Dec 4, 2024 |
32Monitor | CVE-2025-11720No exploit | Spoofing risk in Android custom tabsmozilla · firefox · CWE-451 | High8.1 | — | 0.3% | Oct 14, 2025 |
32Monitor | CVE-2024-52271No exploit | PDF Document Spoofing in Documensodocumenso · documenso · CWE-451 | High8.2 | — | 0.2% | Dec 5, 2024 |
32Monitor | CVE-2024-52277No exploit | PDF Document Spoofing in DocuSealdocuseal · docuseal · CWE-451 | High8.2 | — | 0.2% | Dec 4, 2024 |
32Monitor | CVE-2024-52270No exploit | PDF Document Spoofing in DropBox Sign(HelloSign)dropbox(hellosign) · dropbox sign · CWE-451 | High8.2 | — | 0.2% | Dec 5, 2024 |
31Monitor | CVE-2024-38197No exploit | Microsoft Teams for iOS Spoofing Vulnerabilitymicrosoft · teams · CWE-451 | Medium6.5 | — | 16.1% | Aug 13, 2024 |
31Monitor | CVE-2022-23646No exploit | Improper CSP in Image Optimization API for Next.jsvercel · next.js · CWE-451 | High7.5 | — | 1.8% | Feb 17, 2022 |
- CVE-2024-3811285Now
Windows MSHTML Platform Spoofing Vulnerability
HighCVSS 7.5KEVWeaponizedEPSS 84%microsoft · windows 10 1507Jul 9, 2024
- CVE-2024-4346181Now
Windows MSHTML Platform Spoofing Vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 54%microsoft · windows 10 1507Sep 10, 2024
- CVE-2026-090742Plan
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted H
CriticalCVSS 9.8No exploitEPSS 9%google · chromeJan 20, 2026
- CVE-2025-949139Monitor
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability
MediumCVSS 4.6Proof of conceptEPSS 69%microsoft · windows 11 23h2Aug 26, 2025
- CVE-2026-263439Monitor
Spoofed web content presented under trusted domains using scripted navigation on Firefox iOS
CriticalCVSS 9.8No exploitEPSS 0%mozilla · firefoxFeb 24, 2026
- CVE-2025-804339Monitor
Incorrect URL truncation
CriticalCVSS 9.8No exploitEPSS 0%mozilla · firefoxJul 22, 2025
- CVE-2026-090639Monitor
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (UR
CriticalCVSS 9.8No exploitEPSS 0%google · chromeJan 20, 2026
- CVE-2021-4159835Monitor
UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user
HighCVSS 8.8No exploitEPSS 1%github · enterprise serverJan 25, 2022
- CVE-2021-2286635Monitor
UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resources
HighCVSS 8.8No exploitEPSS 1%github · enterprise serverMay 14, 2021
- CVE-2024-075035Monitor
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions.
HighCVSS 8.8No exploitEPSS 1%mozilla · firefoxJan 23, 2024
- CVE-2020-923635Monitor
There is an improper interface design vulnerability in Huawei product.
HighCVSS 8.8No exploitEPSS 0%huawei · fusioncomputeDec 27, 2024
- CVE-2026-1117535Monitor
Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a
HighCVSS 8.8No exploitEPSS 0%google · chromeJun 4, 2026
- CVE-2026-1117235Monitor
Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing
HighCVSS 8.8No exploitEPSS 0%google · chromeJun 4, 2026
- CVE-2026-5382934Monitor
OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display
HighCVSS 8.5No exploitEPSS 0%openclaw · openclawJun 12, 2026
- CVE-2019-2571834Monitor
Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass
HighCVSS 8.6No exploitEPSS 0%draeger · infinity explorer c700 firmwareJun 1, 2026
- CVE-2024-4904033Monitor
Microsoft Exchange Server Spoofing Vulnerability
HighCVSS 7.5No exploitEPSS 8%microsoft · exchange serverNov 12, 2024
- CVE-2024-5227632Monitor
PDF Document Spoofing in DocuSign
HighCVSS 8.2No exploitEPSS 0%docusign · docusignDec 4, 2024
- CVE-2026-7901132Monitor
UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass sy
HighCVSS 8.1No exploitEPSS 0%google · chromeAug 25, 2026
- CVE-2024-5226932Monitor
AI Assistant PDF Document Spoofing in DocuSign
HighCVSS 8.2No exploitEPSS 0%docusign · docusignDec 4, 2024
- CVE-2025-1172032Monitor
Spoofing risk in Android custom tabs
HighCVSS 8.1No exploitEPSS 0%mozilla · firefoxOct 14, 2025
- CVE-2024-5227132Monitor
PDF Document Spoofing in Documenso
HighCVSS 8.2No exploitEPSS 0%documenso · documensoDec 5, 2024
- CVE-2024-5227732Monitor
PDF Document Spoofing in DocuSeal
HighCVSS 8.2No exploitEPSS 0%docuseal · docusealDec 4, 2024
- CVE-2024-5227032Monitor
PDF Document Spoofing in DropBox Sign(HelloSign)
HighCVSS 8.2No exploitEPSS 0%dropbox(hellosign) · dropbox signDec 5, 2024
- CVE-2024-3819731Monitor
Microsoft Teams for iOS Spoofing Vulnerability
MediumCVSS 6.5No exploitEPSS 16%microsoft · teamsAug 13, 2024
- CVE-2022-2364631Monitor
Improper CSP in Image Optimization API for Next.js
HighCVSS 7.5No exploitEPSS 2%vercel · next.jsFeb 17, 2022