User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The Saa
In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a cli
Windows MSHTML Platform Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. 1. Disp
IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convince
Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into gr
Microsoft Teams for iOS Spoofing Vulnerability
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the ad
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to
phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record compon
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform d
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoo
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as t
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to p
Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a
Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform U
Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perfor
Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinc
Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a use
Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI
Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.8
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 p
User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displaye
User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Sp
User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Display
Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote at
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentiall
Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who
Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who
Inappropriate implementation in Extensions API in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be gran
mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger
The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15
Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security
A malicious website that could create a popup could have resized the popup to overlay the address bar with its own conte
Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without
Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User In
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to an
In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information
A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected b
Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed un
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
A Drag and Drop spoof vulnerability was discovered in F-Secure SAFE Browser for Android and iOS version 19.0 and below.
Frequently Asked Questions
What is CWE-451?
CWE-451 (CWE-451) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-451?
There are 365 CVE records associated with CWE-451 in our database. Of these, 4 are critical severity, 31 are high severity, and 303 are medium severity.
How can I protect against CWE-451 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-451 using AI-powered security agents.
Detect CWE-451 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-451 vulnerabilities across your infrastructure.
Get Started