Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-451

MITRE ↗

CWE-451

4
CRITICAL
31
HIGH
303
MEDIUM
19
LOW
363 CVEs · Page 7/8
8.1
CVE-2024-52269

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The Saa

7.8
CVE-2024-23708

In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a cli

7.5
CVE-2024-38112 KEV

Windows MSHTML Platform Spoofing Vulnerability

7.5
CVE-2024-49040

Microsoft Exchange Server Spoofing Vulnerability

7.5
CVE-2024-52276

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. 1. Disp

6.5
CVE-2023-50938

IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a

6.5
CVE-2024-4950

Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convince

6.5
CVE-2023-7011

Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to

6.5
CVE-2024-7529

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into gr

6.5
CVE-2024-38197

Microsoft Teams for iOS Spoofing Vulnerability

6.1
CVE-2024-5698

By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the ad

5.4
CVE-2024-30055

Microsoft Edge (Chromium-based) Spoofing Vulnerability

5.3
CVE-2024-47044

Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to

4.9
CVE-2024-55889

phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record compon

4.7
CVE-2024-38082

Microsoft Edge (Chromium-based) Spoofing Vulnerability

4.3
CVE-2024-0805

Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform d

4.3
CVE-2024-2631

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoo

4.3
CVE-2024-38313

In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as t

4.3
CVE-2024-38093

Microsoft Edge (Chromium-based) Spoofing Vulnerability

4.3
CVE-2024-6610

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to p

4.3
CVE-2024-6999

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a

4.3
CVE-2024-8909

Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform U

4.3
CVE-2023-7281

Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perfor

4.3
CVE-2023-7282

Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinc

4.3
CVE-2024-7019

Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a use

4.3
CVE-2024-7020

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI

3.5
CVE-2024-51749

Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.8

3.0
CVE-2024-6595

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 p

CVE-2024-52277

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displaye

CVE-2024-52270

User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Sp

CVE-2024-52271

User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Display

6.5
CVE-2023-0130

Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote at

6.5
CVE-2023-0700

Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentiall

4.3
CVE-2023-2937

Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who

4.3
CVE-2023-2938

Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who

4.3
CVE-2023-2941

Inappropriate implementation in Extensions API in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced

8.8
CVE-2021-41598

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be gran

8.1
CVE-2022-39258

mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger

6.5
CVE-2022-32816

The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15

6.5
CVE-2022-3313

Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security

6.5
CVE-2022-34479

A malicious website that could create a popup could have resized the popup to overlay the address bar with its own conte

6.5
CVE-2022-45404

Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without

5.9
CVE-2022-23646

Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User In

5.5
CVE-2021-27414

An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to an

5.3
CVE-2022-20530

In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information

4.3
CVE-2022-2800

A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected b

4.3
CVE-2022-22762

Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed un

4.3
CVE-2022-26383

When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This

4.2
CVE-2021-27773

This vulnerability allows users to execute a clickjacking attack in the meeting's chat.

3.5
CVE-2022-38163

A Drag and Drop spoof vulnerability was discovered in F-Secure SAFE Browser for Android and iOS version 19.0 and below.

Frequently Asked Questions

What is CWE-451?

CWE-451 (CWE-451) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-451?

There are 365 CVE records associated with CWE-451 in our database. Of these, 4 are critical severity, 31 are high severity, and 303 are medium severity.

How can I protect against CWE-451 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-451 using AI-powered security agents.

Detect CWE-451 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-451 vulnerabilities across your infrastructure.

Get Started