Перейти к содержимому
Noroxi

CWE-356 · 32 записей

Product UI does not Warn User of Unsafe Actions

CVE этого класса

32 записей

  • CVE-2018-16858
    59В плане

    It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute

    КритическаяCVSS 9,8Готовый эксплойтEPSS 67 %

    libreoffice · libreoffice25 мар. 2019 г.

  • CVE-2019-6737
    36Наблюдать

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    bitdefender · safepay3 июн. 2019 г.

  • CVE-2019-6736
    36Наблюдать

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    bitdefender · safepay3 июн. 2019 г.

  • CVE-2019-6738
    36Наблюдать

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    bitdefender · safepay3 июн. 2019 г.

  • CVE-2019-13322
    36Наблюдать

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    mi · mi browser10 февр. 2020 г.

  • CVE-2022-39362
    35Наблюдать

    Metabase vulnerable to arbitrary SQL execution from queryhash

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    metabase · metabase26 окт. 2022 г.

  • CVE-2025-2450
    35Наблюдать

    NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    ni · vision builder ai18 мар. 2025 г.

  • CVE-2025-3909
    32Наблюдать

    JavaScript Execution via Spoofed PDF Attachment and file:/// Link

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    mozilla · thunderbird14 мая 2025 г.

  • CVE-2025-3839
    32Наблюдать

    Epiphany: insecure external protocol invocation in epiphany

    ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %

    23 янв. 2026 г.

  • CVE-2026-25805
    32Наблюдать

    Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.

    ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %

    zed · zed10 февр. 2026 г.

  • CVE-2022-35873
    31Наблюдать

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    inductiveautomation · ignition25 июл. 2022 г.

  • CVE-2022-36970
    31Наблюдать

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    aveva · aveva edge29 мар. 2023 г.

  • CVE-2026-0777
    31Наблюдать

    Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    xmind · xmind20 февр. 2026 г.

  • CVE-2025-14403
    31Наблюдать

    PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    pdfsam · enhanced23 дек. 2025 г.

  • CVE-2025-14415
    31Наблюдать

    Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    sodapdf · soda pdf23 дек. 2025 г.

  • CVE-2025-14414
    31Наблюдать

    Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    sodapdf · soda pdf desktop23 дек. 2025 г.

  • CVE-2025-14417
    31Наблюдать

    pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    pdfforge · pdf architect23 дек. 2025 г.

  • CVE-2025-14412
    31Наблюдать

    Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    sodapdf · soda pdf23 дек. 2025 г.

  • CVE-2026-28593
    31Наблюдать

    In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    google · android8 сент. 2026 г.

  • CVE-2025-58335
    30Наблюдать

    In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    jetbrains · junie28 авг. 2025 г.

  • CVE-2025-14402
    28Наблюдать

    PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    pdfsam · enhanced23 дек. 2025 г.

  • CVE-2025-14404
    28Наблюдать

    PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    pdfsam · enhanced23 дек. 2025 г.

  • CVE-2025-14416
    28Наблюдать

    pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    pdfforge · pdf architect23 дек. 2025 г.

  • CVE-2025-14418
    28Наблюдать

    pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    pdfforge · pdf architect23 дек. 2025 г.

  • CVE-2025-31334
    27Наблюдать

    Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    rarlab · winrar3 апр. 2025 г.

Все классы уязвимостей