Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the content
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoo
Malicious scripts could cause desynchronization between the address bar and web content before a response is received in
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a
Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to
Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perfor
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk
OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide com
In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to mislea
In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of priv
In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to cert
In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to mi
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerabilit
Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to versio
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.5 and i
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and
Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attack
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays e
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack
Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform U
Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who c
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinc
OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw
Incorrect security UI in WebAppInstalls in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI
Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perfo
Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.
Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to per
LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced
Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker wh
Inappropriate implementation in Cronet in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to p
Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain s
Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domai
Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform do
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker
Inappropriate implementation in MediaCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had c
Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI sp
Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform
Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had co
Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI sp
Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI
Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI s
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 an
Frequently Asked Questions
What is CWE-451?
CWE-451 (CWE-451) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-451?
There are 225 CVE records associated with CWE-451 in our database. Of these, 3 are critical severity, 18 are high severity, and 192 are medium severity.
How can I protect against CWE-451 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-451 using AI-powered security agents.
Detect CWE-451 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-451 vulnerabilities across your infrastructure.
Get Started