Skip to main content

CWE archive

CWE-451 CVEs

Programmatic archive

308 CVEs tagged with CWE-4514 Critical, 35 High, 250 Medium, 19 Low, 0 Unrated.

CVE-2025-14019

Published Dec 15, 2025

LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen warning prompt, potenti…

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-46287

Published Dec 12, 2025

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62223

Published Dec 5, 2025

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-31266

Published Nov 21, 2025

A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13082

Published Nov 18, 2025

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13102

Published Nov 14, 2025

Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chrom…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7021

Published Nov 14, 2025

Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium sec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11919

Published Nov 14, 2025

Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium secu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12729

Published Nov 10, 2025

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to per…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12435

Published Nov 10, 2025

Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security se…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12911

Published Nov 8, 2025

Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security se…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11213

Published Nov 6, 2025

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perf…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-11212

Published Nov 6, 2025

Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perfor…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-11720

Published Oct 14, 2025

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-11718

Published Oct 14, 2025

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulner…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6429

Published Sep 23, 2025

A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain conditions, error messages are passed through URL parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10290

Published Sep 16, 2025

Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the toolbar correctly, allowing attackers to spoof websites if…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-43327

Published Sep 15, 2025

The issue was addressed by adding additional logic. This issue is fixed in Safari 26, macOS Tahoe 26. Visiting a malicious website may lead to address bar spoofing.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9867

Published Sep 3, 2025

Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium se…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 308 CVEsPage 8 of 13