IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames. This vuln
User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized
Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convin
Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced
Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform U
IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim.
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who
Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker t
Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform
LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the ful
Microsoft Edge for IOS and Android Spoofing Vulnerability
Microsoft Outlook Spoofing Vulnerability
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. T
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker
Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinc
A vulnerability was found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. It has been rated as problematic. This i
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker w
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoi
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url coul
The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malic
Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack.
A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain
Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform
Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to
Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform
Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to
Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote atta
Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform
User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofin
A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is f
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker
The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could all
Incorrect security UI in SplitView in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a use
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker wh
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker wh
A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.
LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific l
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal esc
LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app
Microsoft Edge (Chromium-based) Spoofing Vulnerability
JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipst
A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting
Windows MSHTML Platform Spoofing Vulnerability
There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does no
Frequently Asked Questions
What is CWE-451?
CWE-451 (CWE-451) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-451?
There are 365 CVE records associated with CWE-451 in our database. Of these, 4 are critical severity, 31 are high severity, and 303 are medium severity.
How can I protect against CWE-451 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-451 using AI-powered security agents.
Detect CWE-451 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-451 vulnerabilities across your infrastructure.
Get Started