Skip to main content

CWE archive

CWE-1021 CVEs

Programmatic archive

399 CVEs tagged with CWE-10217 Critical, 90 High, 283 Medium, 19 Low, 0 Unrated.

CVE-2025-49139

Published Jun 9, 2025

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can create a website block to load another s…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5267

Published May 27, 2025

A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in Firefox 139, Firefox…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43854

Published Apr 28, 2025

DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing maliciou…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-32385

Published Apr 16, 2025

EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to display iframes with arbitrary URLs. As the sandbox attribute is…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0362

Published Apr 10, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker cou…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-25213

Published Apr 9, 2025

Improper restriction of rendered UI layers or frames issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views and clicks on the content on the malicious page while logg…

CVSS 6.5 · Medium

CVE-2025-31138

Published Apr 7, 2025

tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensio…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24310

Published Apr 4, 2025

Improper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote unauthenticated attacker to trick the product user to perf…

CVSS 4.3 · Medium

CVE-2025-1923

Published Mar 5, 2025

Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform UI…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1917

Published Mar 5, 2025

Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1940

Published Mar 4, 2025

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpected…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24874

Published Feb 11, 2025

SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the fu…

CVSS 6.8 · Medium

CVE-2024-49796

Published Feb 6, 2025

IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1019

Published Feb 4, 2025

The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability w…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-1018

Published Feb 4, 2025

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-6466

Published Jan 21, 2025

NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified.

CVSS 5.3 · Medium

CVE-2024-56436

Published Jan 8, 2025

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56435

Published Jan 8, 2025

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55888

Published Dec 12, 2024

Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured and m…

CVSS 7.1 · High

CVE-2024-54112

Published Dec 12, 2024

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54110

Published Dec 12, 2024

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53976

Published Nov 26, 2024

Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11700

Published Nov 26, 2024

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external application…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 399 CVEsPage 4 of 16