CWE-356 · 32 kayıt
Product UI does not Warn User of Unsafe Actions
Bu sınıftaki CVE’ler
32 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
59Planlayın | CVE-2018-16858Silahlaştırılmış | It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute libreoffice · libreoffice · CWE-356 | Kritik9,8 | — | %67,3 | 25 Mar 2019 |
36İzleyin | CVE-2019-6737İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.bitdefender · safepay · CWE-356 | Yüksek8,8 | — | %3,8 | 3 Haz 2019 |
36İzleyin | CVE-2019-6736İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.bitdefender · safepay · CWE-356 | Yüksek8,8 | — | %3,7 | 3 Haz 2019 |
36İzleyin | CVE-2019-6738İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.bitdefender · safepay · CWE-356 | Yüksek8,8 | — | %3,7 | 3 Haz 2019 |
36İzleyin | CVE-2019-13322İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0.mi · mi browser · CWE-356 | Yüksek8,8 | — | %2,6 | 10 Şub 2020 |
35İzleyin | CVE-2022-39362İstismar yok | Metabase vulnerable to arbitrary SQL execution from queryhashmetabase · metabase · CWE-356 | Yüksek8,8 | — | %0,9 | 26 Eki 2022 |
35İzleyin | CVE-2025-2450İstismar yok | NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerabilityni · vision builder ai · CWE-356 | Yüksek8,8 | — | %0,5 | 18 Mar 2025 |
32İzleyin | CVE-2025-3909İstismar yok | JavaScript Execution via Spoofed PDF Attachment and file:/// Linkmozilla · thunderbird · CWE-356 | Yüksek8,1 | — | %0,4 | 14 May 2025 |
32İzleyin | CVE-2025-3839İstismar yok | Epiphany: insecure external protocol invocation in epiphanyCWE-356 | Yüksek8,0 | — | %0,4 | 23 Oca 2026 |
32İzleyin | CVE-2026-25805İstismar yok | Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.zed · zed · CWE-356 | Yüksek8,0 | — | %0,4 | 10 Şub 2026 |
31İzleyin | CVE-2022-35873İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-356 | Yüksek7,8 | — | %0,7 | 25 Tem 2022 |
31İzleyin | CVE-2022-36970İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000aveva · aveva edge · CWE-356 | Yüksek7,8 | — | %0,7 | 29 Mar 2023 |
31İzleyin | CVE-2026-0777İstismar yok | Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerabilityxmind · xmind · CWE-356 | Yüksek7,8 | — | %0,3 | 20 Şub 2026 |
31İzleyin | CVE-2025-14403İstismar yok | PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerabilitypdfsam · enhanced · CWE-356 | Yüksek7,8 | — | %0,3 | 23 Ara 2025 |
31İzleyin | CVE-2025-14415İstismar yok | Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerabilitysodapdf · soda pdf · CWE-356 | Yüksek7,8 | — | %0,3 | 23 Ara 2025 |
31İzleyin | CVE-2025-14414İstismar yok | Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerabilitysodapdf · soda pdf desktop · CWE-356 | Yüksek7,8 | — | %0,2 | 23 Ara 2025 |
31İzleyin | CVE-2025-14417İstismar yok | pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerabilitypdfforge · pdf architect · CWE-356 | Yüksek7,8 | — | %0,2 | 23 Ara 2025 |
31İzleyin | CVE-2025-14412İstismar yok | Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerabilitysodapdf · soda pdf · CWE-356 | Yüksek7,8 | — | %0,2 | 23 Ara 2025 |
31İzleyin | CVE-2026-28593İstismar yok | In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI.google · android · CWE-356 | Yüksek7,8 | — | %0,1 | 8 Eyl 2026 |
30İzleyin | CVE-2025-58335İstismar yok | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28jetbrains · junie · CWE-356 | Yüksek7,5 | — | %0,2 | 28 Ağu 2025 |
28İzleyin | CVE-2025-14402İstismar yok | PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfsam · enhanced · CWE-356 | Yüksek7,0 | — | %0,3 | 23 Ara 2025 |
28İzleyin | CVE-2025-14404İstismar yok | PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfsam · enhanced · CWE-356 | Yüksek7,0 | — | %0,3 | 23 Ara 2025 |
28İzleyin | CVE-2025-14416İstismar yok | pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfforge · pdf architect · CWE-356 | Yüksek7,0 | — | %0,2 | 23 Ara 2025 |
28İzleyin | CVE-2025-14418İstismar yok | pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerabilitypdfforge · pdf architect · CWE-356 | Yüksek7,0 | — | %0,2 | 23 Ara 2025 |
27İzleyin | CVE-2025-31334İstismar yok | Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable filerarlab · winrar · CWE-356 | Orta6,8 | — | %1,2 | 3 Nis 2025 |
- CVE-2018-1685859Planlayın
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute
KritikCVSS 9,8SilahlaştırılmışEPSS %67libreoffice · libreoffice25 Mar 2019
- CVE-2019-673736İzleyin
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.
YüksekCVSS 8,8İstismar yokEPSS %4bitdefender · safepay3 Haz 2019
- CVE-2019-673636İzleyin
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.
YüksekCVSS 8,8İstismar yokEPSS %4bitdefender · safepay3 Haz 2019
- CVE-2019-673836İzleyin
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34.
YüksekCVSS 8,8İstismar yokEPSS %4bitdefender · safepay3 Haz 2019
- CVE-2019-1332236İzleyin
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0.
YüksekCVSS 8,8İstismar yokEPSS %3mi · mi browser10 Şub 2020
- CVE-2022-3936235İzleyin
Metabase vulnerable to arbitrary SQL execution from queryhash
YüksekCVSS 8,8İstismar yokEPSS %1metabase · metabase26 Eki 2022
- CVE-2025-245035İzleyin
NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1ni · vision builder ai18 Mar 2025
- CVE-2025-390932İzleyin
JavaScript Execution via Spoofed PDF Attachment and file:/// Link
YüksekCVSS 8,1İstismar yokEPSS %0mozilla · thunderbird14 May 2025
- CVE-2025-383932İzleyin
Epiphany: insecure external protocol invocation in epiphany
YüksekCVSS 8,0İstismar yokEPSS %023 Oca 2026
- CVE-2026-2580532İzleyin
Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.
YüksekCVSS 8,0İstismar yokEPSS %0zed · zed10 Şub 2026
- CVE-2022-3587331İzleyin
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
YüksekCVSS 7,8İstismar yokEPSS %1inductiveautomation · ignition25 Tem 2022
- CVE-2022-3697031İzleyin
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000
YüksekCVSS 7,8İstismar yokEPSS %1aveva · aveva edge29 Mar 2023
- CVE-2026-077731İzleyin
Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0xmind · xmind20 Şub 2026
- CVE-2025-1440331İzleyin
PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0pdfsam · enhanced23 Ara 2025
- CVE-2025-1441531İzleyin
Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0sodapdf · soda pdf23 Ara 2025
- CVE-2025-1441431İzleyin
Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0sodapdf · soda pdf desktop23 Ara 2025
- CVE-2025-1441731İzleyin
pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0pdfforge · pdf architect23 Ara 2025
- CVE-2025-1441231İzleyin
Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0sodapdf · soda pdf23 Ara 2025
- CVE-2026-2859331İzleyin
In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI.
YüksekCVSS 7,8İstismar yokEPSS %0google · android8 Eyl 2026
- CVE-2025-5833530İzleyin
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28
YüksekCVSS 7,5İstismar yokEPSS %0jetbrains · junie28 Ağu 2025
- CVE-2025-1440228İzleyin
PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability
YüksekCVSS 7,0İstismar yokEPSS %0pdfsam · enhanced23 Ara 2025
- CVE-2025-1440428İzleyin
PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability
YüksekCVSS 7,0İstismar yokEPSS %0pdfsam · enhanced23 Ara 2025
- CVE-2025-1441628İzleyin
pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability
YüksekCVSS 7,0İstismar yokEPSS %0pdfforge · pdf architect23 Ara 2025
- CVE-2025-1441828İzleyin
pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability
YüksekCVSS 7,0İstismar yokEPSS %0pdfforge · pdf architect23 Ara 2025
- CVE-2025-3133427İzleyin
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file
OrtaCVSS 6,8İstismar yokEPSS %1rarlab · winrar3 Nis 2025