CWE-451 · 380 записей
User Interface (UI) Misrepresentation of Critical Information
CVE этого класса
380 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
85Срочно | CVE-2024-38112Готовый эксплойт | Windows MSHTML Platform Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-451 | Высокая7,5 | KEV | 84,2 % | 9 июл. 2024 г. |
81Срочно | CVE-2024-43461Готовый эксплойт | Windows MSHTML Platform Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-451 | Высокая8,8 | KEV | 54,5 % | 10 сент. 2024 г. |
42В плане | CVE-2026-0907Эксплойта нет | Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted Hgoogle · chrome · CWE-451 | Критическая9,8 | — | 8,6 % | 20 янв. 2026 г. |
39Наблюдать | CVE-2025-9491Proof of concept | Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerabilitymicrosoft · windows 11 23h2 · CWE-451 | Средняя4,6 | — | 68,9 % | 26 авг. 2025 г. |
39Наблюдать | CVE-2026-2634Эксплойта нет | Spoofed web content presented under trusted domains using scripted navigation on Firefox iOSmozilla · firefox · CWE-451 | Критическая9,8 | — | 0,5 % | 24 февр. 2026 г. |
39Наблюдать | CVE-2025-8043Эксплойта нет | Incorrect URL truncationmozilla · firefox · CWE-451 | Критическая9,8 | — | 0,4 % | 22 июл. 2025 г. |
39Наблюдать | CVE-2026-0906Эксплойта нет | Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URgoogle · chrome · CWE-451 | Критическая9,8 | — | 0,3 % | 20 янв. 2026 г. |
35Наблюдать | CVE-2021-41598Эксплойта нет | UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to usergithub · enterprise server · CWE-451 | Высокая8,8 | — | 1,2 % | 25 янв. 2022 г. |
35Наблюдать | CVE-2021-22866Эксплойта нет | UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resourcesgithub · enterprise server · CWE-451 | Высокая8,8 | — | 1,0 % | 14 мая 2021 г. |
35Наблюдать | CVE-2024-0750Эксплойта нет | A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions.mozilla · firefox · CWE-451 | Высокая8,8 | — | 0,8 % | 23 янв. 2024 г. |
35Наблюдать | CVE-2020-9236Эксплойта нет | There is an improper interface design vulnerability in Huawei product.huawei · fusioncompute · CWE-451 | Высокая8,8 | — | 0,4 % | 27 дек. 2024 г. |
35Наблюдать | CVE-2026-11175Эксплойта нет | Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a google · chrome · CWE-451 | Высокая8,8 | — | 0,2 % | 4 июн. 2026 г. |
35Наблюдать | CVE-2026-11172Эксплойта нет | Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing google · chrome · CWE-451 | Высокая8,8 | — | 0,2 % | 4 июн. 2026 г. |
34Наблюдать | CVE-2026-53829Эксплойта нет | OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Displayopenclaw · openclaw · CWE-451 | Высокая8,5 | — | 0,4 % | 12 июн. 2026 г. |
34Наблюдать | CVE-2019-25718Эксплойта нет | Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypassdraeger · infinity explorer c700 firmware · CWE-451 | Высокая8,6 | — | 0,1 % | 1 июн. 2026 г. |
33Наблюдать | CVE-2024-49040Эксплойта нет | Microsoft Exchange Server Spoofing Vulnerabilitymicrosoft · exchange server · CWE-451 | Высокая7,5 | — | 8,5 % | 12 нояб. 2024 г. |
32Наблюдать | CVE-2024-52276Эксплойта нет | PDF Document Spoofing in DocuSigndocusign · docusign · CWE-451 | Высокая8,2 | — | 0,4 % | 4 дек. 2024 г. |
32Наблюдать | CVE-2026-79011Эксплойта нет | UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass sygoogle · chrome · CWE-451 | Высокая8,1 | — | 0,3 % | 25 авг. 2026 г. |
32Наблюдать | CVE-2024-52269Эксплойта нет | AI Assistant PDF Document Spoofing in DocuSigndocusign · docusign · CWE-451 | Высокая8,2 | — | 0,3 % | 4 дек. 2024 г. |
32Наблюдать | CVE-2025-11720Эксплойта нет | Spoofing risk in Android custom tabsmozilla · firefox · CWE-451 | Высокая8,1 | — | 0,3 % | 14 окт. 2025 г. |
32Наблюдать | CVE-2024-52271Эксплойта нет | PDF Document Spoofing in Documensodocumenso · documenso · CWE-451 | Высокая8,2 | — | 0,2 % | 5 дек. 2024 г. |
32Наблюдать | CVE-2024-52277Эксплойта нет | PDF Document Spoofing in DocuSealdocuseal · docuseal · CWE-451 | Высокая8,2 | — | 0,2 % | 4 дек. 2024 г. |
32Наблюдать | CVE-2024-52270Эксплойта нет | PDF Document Spoofing in DropBox Sign(HelloSign)dropbox(hellosign) · dropbox sign · CWE-451 | Высокая8,2 | — | 0,2 % | 5 дек. 2024 г. |
31Наблюдать | CVE-2024-38197Эксплойта нет | Microsoft Teams for iOS Spoofing Vulnerabilitymicrosoft · teams · CWE-451 | Средняя6,5 | — | 16,1 % | 13 авг. 2024 г. |
31Наблюдать | CVE-2022-23646Эксплойта нет | Improper CSP in Image Optimization API for Next.jsvercel · next.js · CWE-451 | Высокая7,5 | — | 1,8 % | 17 февр. 2022 г. |
- CVE-2024-3811285Срочно
Windows MSHTML Platform Spoofing Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 84 %microsoft · windows 10 15079 июл. 2024 г.
- CVE-2024-4346181Срочно
Windows MSHTML Platform Spoofing Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 54 %microsoft · windows 10 150710 сент. 2024 г.
- CVE-2026-090742В плане
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted H
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %google · chrome20 янв. 2026 г.
- CVE-2025-949139Наблюдать
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability
СредняяCVSS 4,6Proof of conceptEPSS 69 %microsoft · windows 11 23h226 авг. 2025 г.
- CVE-2026-263439Наблюдать
Spoofed web content presented under trusted domains using scripted navigation on Firefox iOS
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %mozilla · firefox24 февр. 2026 г.
- CVE-2025-804339Наблюдать
Incorrect URL truncation
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %mozilla · firefox22 июл. 2025 г.
- CVE-2026-090639Наблюдать
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (UR
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %google · chrome20 янв. 2026 г.
- CVE-2021-4159835Наблюдать
UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %github · enterprise server25 янв. 2022 г.
- CVE-2021-2286635Наблюдать
UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resources
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %github · enterprise server14 мая 2021 г.
- CVE-2024-075035Наблюдать
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mozilla · firefox23 янв. 2024 г.
- CVE-2020-923635Наблюдать
There is an improper interface design vulnerability in Huawei product.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %huawei · fusioncompute27 дек. 2024 г.
- CVE-2026-1117535Наблюдать
Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %google · chrome4 июн. 2026 г.
- CVE-2026-1117235Наблюдать
Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %google · chrome4 июн. 2026 г.
- CVE-2026-5382934Наблюдать
OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %openclaw · openclaw12 июн. 2026 г.
- CVE-2019-2571834Наблюдать
Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %draeger · infinity explorer c700 firmware1 июн. 2026 г.
- CVE-2024-4904033Наблюдать
Microsoft Exchange Server Spoofing Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %microsoft · exchange server12 нояб. 2024 г.
- CVE-2024-5227632Наблюдать
PDF Document Spoofing in DocuSign
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %docusign · docusign4 дек. 2024 г.
- CVE-2026-7901132Наблюдать
UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass sy
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %google · chrome25 авг. 2026 г.
- CVE-2024-5226932Наблюдать
AI Assistant PDF Document Spoofing in DocuSign
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %docusign · docusign4 дек. 2024 г.
- CVE-2025-1172032Наблюдать
Spoofing risk in Android custom tabs
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %mozilla · firefox14 окт. 2025 г.
- CVE-2024-5227132Наблюдать
PDF Document Spoofing in Documenso
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %documenso · documenso5 дек. 2024 г.
- CVE-2024-5227732Наблюдать
PDF Document Spoofing in DocuSeal
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %docuseal · docuseal4 дек. 2024 г.
- CVE-2024-5227032Наблюдать
PDF Document Spoofing in DropBox Sign(HelloSign)
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %dropbox(hellosign) · dropbox sign5 дек. 2024 г.
- CVE-2024-3819731Наблюдать
Microsoft Teams for iOS Spoofing Vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 16 %microsoft · teams13 авг. 2024 г.
- CVE-2022-2364631Наблюдать
Improper CSP in Image Optimization API for Next.js
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %vercel · next.js17 февр. 2022 г.