Skip to main content

CWE archive

CWE-451 CVEs

Programmatic archive

308 CVEs tagged with CWE-4514 Critical, 35 High, 250 Medium, 19 Low, 0 Unrated.

CVE-2025-29796

Published Apr 4, 2025

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3074

Published Apr 2, 2025

Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security seve…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3073

Published Apr 2, 2025

Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3072

Published Apr 2, 2025

Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1922

Published Mar 5, 2025

Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker who convinced a user to engage in specific UI gestures to pe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0451

Published Feb 4, 2025

Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-0729

Published Jan 27, 2025

A vulnerability was found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. It has been rated as problematic. This issue affects some unknown processing. The manipulation lead…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
36.0

CVE-2025-21262

Published Jan 24, 2025

User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0446

Published Jan 15, 2025

Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI s…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-0435

Published Jan 15, 2025

Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium s…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2024-55896

Published Jan 3, 2025

IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames.  This vulnerability could allow an attacker to gain improper access a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9236

Published Dec 27, 2024

There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers can exploit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-55889

Published Dec 13, 2024

phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52271

Published Dec 5, 2024

User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Displayed version does not show the layer flattened version, once…

CVSS 8.2 · High

CVE-2024-52270

Published Dec 5, 2024

User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened…

CVSS 8.2 · High

CVE-2024-52269

Published Dec 4, 2024

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The SaaS AI assistant ignores hidden content that is rendered afte…

CVSS 8.2 · High

CVE-2024-52277

Published Dec 4, 2024

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displayed version does not show the layer flattened version, once d…

CVSS 8.2 · High

CVE-2024-52276

Published Dec 4, 2024

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. 1. Displayed version does not show the layer flattened version, wh…

CVSS 8.2 · High
Showing 226-250 of 308 CVEsPage 10 of 13