CWE-356 · 32 записей
Product UI does not Warn User of Unsafe Actions
CVE этого класса
32 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
59В плане | CVE-2018-16858Готовый эксплойт | It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute libreoffice · libreoffice · CWE-356 | Критическая9,8 | — | 67,3 % | 25 мар. 2019 г. |
36Наблюдать | CVE-2019-6737Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.bitdefender · safepay · CWE-356 | Высокая8,8 | — | 3,8 % | 3 июн. 2019 г. |
36Наблюдать | CVE-2019-6736Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.bitdefender · safepay · CWE-356 | Высокая8,8 | — | 3,7 % | 3 июн. 2019 г. |
36Наблюдать | CVE-2019-6738Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.bitdefender · safepay · CWE-356 | Высокая8,8 | — | 3,7 % | 3 июн. 2019 г. |
36Наблюдать | CVE-2019-13322Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0.mi · mi browser · CWE-356 | Высокая8,8 | — | 2,6 % | 10 февр. 2020 г. |
35Наблюдать | CVE-2022-39362Эксплойта нет | Metabase vulnerable to arbitrary SQL execution from queryhashmetabase · metabase · CWE-356 | Высокая8,8 | — | 0,9 % | 26 окт. 2022 г. |
35Наблюдать | CVE-2025-2450Эксплойта нет | NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerabilityni · vision builder ai · CWE-356 | Высокая8,8 | — | 0,5 % | 18 мар. 2025 г. |
32Наблюдать | CVE-2025-3909Эксплойта нет | JavaScript Execution via Spoofed PDF Attachment and file:/// Linkmozilla · thunderbird · CWE-356 | Высокая8,1 | — | 0,4 % | 14 мая 2025 г. |
32Наблюдать | CVE-2025-3839Эксплойта нет | Epiphany: insecure external protocol invocation in epiphanyCWE-356 | Высокая8,0 | — | 0,4 % | 23 янв. 2026 г. |
32Наблюдать | CVE-2026-25805Эксплойта нет | Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.zed · zed · CWE-356 | Высокая8,0 | — | 0,4 % | 10 февр. 2026 г. |
31Наблюдать | CVE-2022-35873Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-356 | Высокая7,8 | — | 0,7 % | 25 июл. 2022 г. |
31Наблюдать | CVE-2022-36970Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000aveva · aveva edge · CWE-356 | Высокая7,8 | — | 0,7 % | 29 мар. 2023 г. |
31Наблюдать | CVE-2026-0777Эксплойта нет | Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerabilityxmind · xmind · CWE-356 | Высокая7,8 | — | 0,3 % | 20 февр. 2026 г. |
31Наблюдать | CVE-2025-14403Эксплойта нет | PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerabilitypdfsam · enhanced · CWE-356 | Высокая7,8 | — | 0,3 % | 23 дек. 2025 г. |
31Наблюдать | CVE-2025-14415Эксплойта нет | Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerabilitysodapdf · soda pdf · CWE-356 | Высокая7,8 | — | 0,3 % | 23 дек. 2025 г. |
31Наблюдать | CVE-2025-14414Эксплойта нет | Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerabilitysodapdf · soda pdf desktop · CWE-356 | Высокая7,8 | — | 0,2 % | 23 дек. 2025 г. |
31Наблюдать | CVE-2025-14417Эксплойта нет | pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerabilitypdfforge · pdf architect · CWE-356 | Высокая7,8 | — | 0,2 % | 23 дек. 2025 г. |
31Наблюдать | CVE-2025-14412Эксплойта нет | Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerabilitysodapdf · soda pdf · CWE-356 | Высокая7,8 | — | 0,2 % | 23 дек. 2025 г. |
31Наблюдать | CVE-2026-28593Эксплойта нет | In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI.google · android · CWE-356 | Высокая7,8 | — | 0,1 % | 8 сент. 2026 г. |
30Наблюдать | CVE-2025-58335Эксплойта нет | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28jetbrains · junie · CWE-356 | Высокая7,5 | — | 0,2 % | 28 авг. 2025 г. |
28Наблюдать | CVE-2025-14402Эксплойта нет | PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfsam · enhanced · CWE-356 | Высокая7,0 | — | 0,3 % | 23 дек. 2025 г. |
28Наблюдать | CVE-2025-14404Эксплойта нет | PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfsam · enhanced · CWE-356 | Высокая7,0 | — | 0,3 % | 23 дек. 2025 г. |
28Наблюдать | CVE-2025-14416Эксплойта нет | pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfforge · pdf architect · CWE-356 | Высокая7,0 | — | 0,2 % | 23 дек. 2025 г. |
28Наблюдать | CVE-2025-14418Эксплойта нет | pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfforge · pdf architect · CWE-356 | Высокая7,0 | — | 0,2 % | 23 дек. 2025 г. |
27Наблюдать | CVE-2025-31334Эксплойта нет | Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable filerarlab · winrar · CWE-356 | Средняя6,8 | — | 1,2 % | 3 апр. 2025 г. |
- CVE-2018-1685859В плане
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute
КритическаяCVSS 9,8Готовый эксплойтEPSS 67 %libreoffice · libreoffice25 мар. 2019 г.
- CVE-2019-673736Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %bitdefender · safepay3 июн. 2019 г.
- CVE-2019-673636Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %bitdefender · safepay3 июн. 2019 г.
- CVE-2019-673836Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %bitdefender · safepay3 июн. 2019 г.
- CVE-2019-1332236Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %mi · mi browser10 февр. 2020 г.
- CVE-2022-3936235Наблюдать
Metabase vulnerable to arbitrary SQL execution from queryhash
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %metabase · metabase26 окт. 2022 г.
- CVE-2025-245035Наблюдать
NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ni · vision builder ai18 мар. 2025 г.
- CVE-2025-390932Наблюдать
JavaScript Execution via Spoofed PDF Attachment and file:/// Link
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %mozilla · thunderbird14 мая 2025 г.
- CVE-2025-383932Наблюдать
Epiphany: insecure external protocol invocation in epiphany
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %23 янв. 2026 г.
- CVE-2026-2580532Наблюдать
Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %zed · zed10 февр. 2026 г.
- CVE-2022-3587331Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %inductiveautomation · ignition25 июл. 2022 г.
- CVE-2022-3697031Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %aveva · aveva edge29 мар. 2023 г.
- CVE-2026-077731Наблюдать
Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %xmind · xmind20 февр. 2026 г.
- CVE-2025-1440331Наблюдать
PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %pdfsam · enhanced23 дек. 2025 г.
- CVE-2025-1441531Наблюдать
Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %sodapdf · soda pdf23 дек. 2025 г.
- CVE-2025-1441431Наблюдать
Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %sodapdf · soda pdf desktop23 дек. 2025 г.
- CVE-2025-1441731Наблюдать
pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %pdfforge · pdf architect23 дек. 2025 г.
- CVE-2025-1441231Наблюдать
Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %sodapdf · soda pdf23 дек. 2025 г.
- CVE-2026-2859331Наблюдать
In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %google · android8 сент. 2026 г.
- CVE-2025-5833530Наблюдать
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %jetbrains · junie28 авг. 2025 г.
- CVE-2025-1440228Наблюдать
PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %pdfsam · enhanced23 дек. 2025 г.
- CVE-2025-1440428Наблюдать
PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %pdfsam · enhanced23 дек. 2025 г.
- CVE-2025-1441628Наблюдать
pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %pdfforge · pdf architect23 дек. 2025 г.
- CVE-2025-1441828Наблюдать
pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %pdfforge · pdf architect23 дек. 2025 г.
- CVE-2025-3133427Наблюдать
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file
СредняяCVSS 6,8Эксплойта нетEPSS 1 %rarlab · winrar3 апр. 2025 г.