İçeriğe atla
Noroxi

CWE-356 · 32 kayıt

Product UI does not Warn User of Unsafe Actions

Bu sınıftaki CVE’ler

32 kayıt

  • CVE-2018-16858
    59Planlayın

    It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute

    KritikCVSS 9,8SilahlaştırılmışEPSS %67

    libreoffice · libreoffice25 Mar 2019

  • CVE-2019-6737
    36İzleyin

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.

    YüksekCVSS 8,8İstismar yokEPSS %4

    bitdefender · safepay3 Haz 2019

  • CVE-2019-6736
    36İzleyin

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.

    YüksekCVSS 8,8İstismar yokEPSS %4

    bitdefender · safepay3 Haz 2019

  • CVE-2019-6738
    36İzleyin

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.

    YüksekCVSS 8,8İstismar yokEPSS %4

    bitdefender · safepay3 Haz 2019

  • CVE-2019-13322
    36İzleyin

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0.

    YüksekCVSS 8,8İstismar yokEPSS %3

    mi · mi browser10 Şub 2020

  • CVE-2022-39362
    35İzleyin

    Metabase vulnerable to arbitrary SQL execution from queryhash

    YüksekCVSS 8,8İstismar yokEPSS %1

    metabase · metabase26 Eki 2022

  • CVE-2025-2450
    35İzleyin

    NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    ni · vision builder ai18 Mar 2025

  • CVE-2025-3909
    32İzleyin

    JavaScript Execution via Spoofed PDF Attachment and file:/// Link

    YüksekCVSS 8,1İstismar yokEPSS %0

    mozilla · thunderbird14 May 2025

  • CVE-2025-3839
    32İzleyin

    Epiphany: insecure external protocol invocation in epiphany

    YüksekCVSS 8,0İstismar yokEPSS %0

    23 Oca 2026

  • CVE-2026-25805
    32İzleyin

    Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.

    YüksekCVSS 8,0İstismar yokEPSS %0

    zed · zed10 Şub 2026

  • CVE-2022-35873
    31İzleyin

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202

    YüksekCVSS 7,8İstismar yokEPSS %1

    inductiveautomation · ignition25 Tem 2022

  • CVE-2022-36970
    31İzleyin

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000

    YüksekCVSS 7,8İstismar yokEPSS %1

    aveva · aveva edge29 Mar 2023

  • CVE-2026-0777
    31İzleyin

    Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %0

    xmind · xmind20 Şub 2026

  • CVE-2025-14403
    31İzleyin

    PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %0

    pdfsam · enhanced23 Ara 2025

  • CVE-2025-14415
    31İzleyin

    Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %0

    sodapdf · soda pdf23 Ara 2025

  • CVE-2025-14414
    31İzleyin

    Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %0

    sodapdf · soda pdf desktop23 Ara 2025

  • CVE-2025-14417
    31İzleyin

    pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %0

    pdfforge · pdf architect23 Ara 2025

  • CVE-2025-14412
    31İzleyin

    Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %0

    sodapdf · soda pdf23 Ara 2025

  • CVE-2026-28593
    31İzleyin

    In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI.

    YüksekCVSS 7,8İstismar yokEPSS %0

    google · android8 Eyl 2026

  • CVE-2025-58335
    30İzleyin

    In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28

    YüksekCVSS 7,5İstismar yokEPSS %0

    jetbrains · junie28 Ağu 2025

  • CVE-2025-14402
    28İzleyin

    PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability

    YüksekCVSS 7,0İstismar yokEPSS %0

    pdfsam · enhanced23 Ara 2025

  • CVE-2025-14404
    28İzleyin

    PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability

    YüksekCVSS 7,0İstismar yokEPSS %0

    pdfsam · enhanced23 Ara 2025

  • CVE-2025-14416
    28İzleyin

    pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability

    YüksekCVSS 7,0İstismar yokEPSS %0

    pdfforge · pdf architect23 Ara 2025

  • CVE-2025-14418
    28İzleyin

    pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability

    YüksekCVSS 7,0İstismar yokEPSS %0

    pdfforge · pdf architect23 Ara 2025

  • CVE-2025-31334
    27İzleyin

    Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file

    OrtaCVSS 6,8İstismar yokEPSS %1

    rarlab · winrar3 Nis 2025

Tüm zafiyet sınıfları