Skip to content
Noroxi

CWE-451 · 380 records

User Interface (UI) Misrepresentation of Critical Information

CVEs in this class

380 records

  • Windows MSHTML Platform Spoofing Vulnerability

    HighCVSS 7.5KEVWeaponizedEPSS 84%

    microsoft · windows 10 1507Jul 9, 2024

  • Windows MSHTML Platform Spoofing Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 54%

    microsoft · windows 10 1507Sep 10, 2024

  • Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted H

    CriticalCVSS 9.8No exploitEPSS 9%

    google · chromeJan 20, 2026

  • CVE-2025-9491
    39Monitor

    Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability

    MediumCVSS 4.6Proof of conceptEPSS 69%

    microsoft · windows 11 23h2Aug 26, 2025

  • CVE-2026-2634
    39Monitor

    Spoofed web content presented under trusted domains using scripted navigation on Firefox iOS

    CriticalCVSS 9.8No exploitEPSS 0%

    mozilla · firefoxFeb 24, 2026

  • CVE-2025-8043
    39Monitor

    Incorrect URL truncation

    CriticalCVSS 9.8No exploitEPSS 0%

    mozilla · firefoxJul 22, 2025

  • CVE-2026-0906
    39Monitor

    Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (UR

    CriticalCVSS 9.8No exploitEPSS 0%

    google · chromeJan 20, 2026

  • UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user

    HighCVSS 8.8No exploitEPSS 1%

    github · enterprise serverJan 25, 2022

  • UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resources

    HighCVSS 8.8No exploitEPSS 1%

    github · enterprise serverMay 14, 2021

  • CVE-2024-0750
    35Monitor

    A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions.

    HighCVSS 8.8No exploitEPSS 1%

    mozilla · firefoxJan 23, 2024

  • CVE-2020-9236
    35Monitor

    There is an improper interface design vulnerability in Huawei product.

    HighCVSS 8.8No exploitEPSS 0%

    huawei · fusioncomputeDec 27, 2024

  • Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a

    HighCVSS 8.8No exploitEPSS 0%

    google · chromeJun 4, 2026

  • Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing

    HighCVSS 8.8No exploitEPSS 0%

    google · chromeJun 4, 2026

  • OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display

    HighCVSS 8.5No exploitEPSS 0%

    openclaw · openclawJun 12, 2026

  • Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass

    HighCVSS 8.6No exploitEPSS 0%

    draeger · infinity explorer c700 firmwareJun 1, 2026

  • Microsoft Exchange Server Spoofing Vulnerability

    HighCVSS 7.5No exploitEPSS 8%

    microsoft · exchange serverNov 12, 2024

  • PDF Document Spoofing in DocuSign

    HighCVSS 8.2No exploitEPSS 0%

    docusign · docusignDec 4, 2024

  • UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass sy

    HighCVSS 8.1No exploitEPSS 0%

    google · chromeAug 25, 2026

  • AI Assistant PDF Document Spoofing in DocuSign

    HighCVSS 8.2No exploitEPSS 0%

    docusign · docusignDec 4, 2024

  • Spoofing risk in Android custom tabs

    HighCVSS 8.1No exploitEPSS 0%

    mozilla · firefoxOct 14, 2025

  • PDF Document Spoofing in Documenso

    HighCVSS 8.2No exploitEPSS 0%

    documenso · documensoDec 5, 2024

  • PDF Document Spoofing in DocuSeal

    HighCVSS 8.2No exploitEPSS 0%

    docuseal · docusealDec 4, 2024

  • PDF Document Spoofing in DropBox Sign(HelloSign)

    HighCVSS 8.2No exploitEPSS 0%

    dropbox(hellosign) · dropbox signDec 5, 2024

  • Microsoft Teams for iOS Spoofing Vulnerability

    MediumCVSS 6.5No exploitEPSS 16%

    microsoft · teamsAug 13, 2024

  • Improper CSP in Image Optimization API for Next.js

    HighCVSS 7.5No exploitEPSS 2%

    vercel · next.jsFeb 17, 2022

All vulnerability classes