CWE-1021: CWE-1021

68
Total CVEs
3
Critical
28
High
6.4
Avg CVSS

Yearly Trend

2026
9
2025
28
2024
15
2023
2
2022
4

Top Affected Vendors

1 Google 23
2 Mozilla 7
3 Ibm 4
4 Huawei 3
5 Gitlab 2
6 Sick 2
7 Wegia 1
8 Xwiki 1
9 Ruoyi 1
10 Freshrss 1

All CWE-1021 CVEs (68)

CVE-2021-23274
9.8

This CVE describes a clickjacking vulnerability in TIBCO API Exchange Gateway's Config UI component that allows unauthenticated attackers with network...

Mar 23, 2021
CVE-2021-21132
9.6

This vulnerability in Chrome DevTools allowed malicious Chrome extensions to escape the browser's security sandbox. Attackers could potentially execut...

Feb 9, 2021
CVE-2024-10004
9.1

This vulnerability in Firefox for iOS causes the browser to incorrectly display an HTTPS padlock icon when opening an external HTTP link after the app...

Oct 15, 2024
CVE-2023-41897
8.8

This vulnerability in Home Assistant allows attackers to perform clickjacking attacks by tricking users into clicking malicious elements on a page. Th...

Oct 19, 2023
CVE-2021-3734
8.8

CVE-2021-3734 is a clickjacking vulnerability in YOURLS URL shortener software that allows attackers to overlay malicious UI elements over legitimate ...

Aug 26, 2021
CVE-2024-11700
8.1

This CVE describes a tapjacking vulnerability in Firefox and Thunderbird where malicious websites could trick users into approving external applicatio...

Nov 26, 2024
CVE-2024-7523
8.1

This vulnerability allows malicious websites to partially obscure security permission prompts in Firefox for Android, potentially tricking users into ...

Aug 6, 2024
CVE-2024-33377
8.1

This clickjacking vulnerability in LB-LINK BL-W1210M routers allows attackers to trick authenticated administrators into performing unintended actions...

Jun 14, 2024
CVE-2025-48597
7.8

This CVE describes a tapjacking/overlay vulnerability in Android that allows attackers to trick users into granting permissions without their knowledg...

Dec 8, 2025
CVE-2025-32349
7.8

This CVE describes a tapjacking/overlay vulnerability in Android that allows malicious apps to draw over legitimate apps and intercept user taps, pote...

Sep 4, 2025
CVE-2024-34743
7.8

This vulnerability in Android's SurfaceFlinger component allows local privilege escalation through tapjacking due to a logic error. Attackers can expl...

Aug 15, 2024
CVE-2022-20443
7.8

This CVE describes a tapjacking/overlay vulnerability in Android's Layer.cpp that allows malicious apps to bypass user interaction requirements. Attac...

Jun 28, 2023
CVE-2021-1036
7.8

CVE-2021-1036 is a tapjacking vulnerability in Android's LocationSettingsActivity that allows malicious apps to overlay deceptive UI elements on legit...

Jan 14, 2022
CVE-2021-1039
7.8

This vulnerability allows local attackers to perform a tapjacking/overlay attack on Android's notification access activity, potentially gaining elevat...

Dec 15, 2021
CVE-2021-0586
7.8

This CVE describes a tapjacking vulnerability in Android's Bluetooth device picker interface. Attackers can overlay malicious UI elements to trick use...

Jul 14, 2021
CVE-2025-15032
7.4

This vulnerability in Dia browser on macOS allows attackers to create custom-sized windows without the 'about:blank' indicator, enabling them to spoof...

Jan 16, 2026
CVE-2025-13132
7.4

This vulnerability allows malicious websites to enter fullscreen mode without displaying the standard browser notification, potentially tricking users...

Nov 21, 2025
CVE-2022-22807
7.4

This clickjacking vulnerability allows attackers to trick users into performing unintended actions on the EcoStruxure EV Charging Expert web interface...

Feb 9, 2022
CVE-2025-48639
7.3

This CVE describes a tapjacking/overlay vulnerability in Android's DefaultTransitionHandler that allows malicious apps to trick users into granting pe...

Dec 8, 2025
CVE-2025-22417
7.3

This CVE describes a tapjacking/overlay vulnerability in Android's Transition framework that allows malicious apps to bypass touch filtering restricti...

Sep 2, 2025
CVE-2025-22419
7.3

This CVE describes a tapjacking/overlay vulnerability in Android's Telephony service that could trick users into enabling malicious call forwarding. A...

Sep 2, 2025
CVE-2024-31324
7.3

This Android vulnerability allows attackers to bypass tapjacking/overlay protection by manipulating screen orientation during activity launches. It en...

Jul 9, 2024
CVE-2021-39691
7.3

This CVE describes a tapjacking vulnerability in Android's WindowManager that allows malicious apps to overlay deceptive UI elements over legitimate a...

Jun 15, 2022
CVE-2021-39796
7.3

This Android vulnerability allows malicious apps to trick users into installing harmful applications through a tapjacking/overlay attack. Attackers ca...

Apr 12, 2022
CVE-2021-1016
7.3

This vulnerability allows malicious apps to trick users into granting USB access permissions without their informed consent through a tapjacking/overl...

Dec 15, 2021
CVE-2021-0583
7.3

This CVE describes a tapjacking/overlay vulnerability in Android's Bluetooth pairing dialog that allows malicious apps to trick users into enabling Bl...

Oct 11, 2021
CVE-2021-0598
7.3

This vulnerability allows attackers to trick users into pairing with malicious Bluetooth devices through a tapjacking/overlay attack. It affects Andro...

Oct 6, 2021
CVE-2021-0538
7.3

This vulnerability allows attackers to trick users into tapping on malicious overlays that exit emergency callback mode, potentially enabling local pr...

Jun 22, 2021
CVE-2025-1940
7.1

This vulnerability allows attackers to partially obscure confirmation prompts in Firefox for Android, tricking users into launching external apps unex...

Mar 4, 2025
CVE-2024-55888
7.1

Hush Line whistleblower management systems running versions 0.1.0 through 0.3.4 lack Content Security Policy and security headers, allowing attackers ...

Dec 12, 2024
CVE-2021-0963
7.1

This Android vulnerability allows malicious apps to trick users into granting certificate access via tapjacking/overlay attacks. Attackers can use thi...

Dec 15, 2021
CVE-2024-7404
6.8

This vulnerability in GitLab's Device OAuth flow allows an attacker to gain full API access as another user through cross-window forgery. It affects G...

Nov 14, 2024
CVE-2024-2177
6.8

A Cross Window Forgery vulnerability in GitLab CE/EE allows attackers to manipulate the OAuth authentication flow via crafted payloads, potentially en...

Jul 9, 2024
CVE-2025-59950
6.7

This vulnerability in FreshRSS allows attackers to trick administrators into promoting unauthorized users to admin privileges through a double clickja...

Sep 30, 2025
CVE-2025-25213
6.5

This vulnerability allows clickjacking attacks on Wi-Fi AP UNIT 'AC-WPS-11ac series' devices. Attackers can trick authenticated users into clicking ma...

Apr 9, 2025
CVE-2024-7518
6.5

This vulnerability allows malicious websites to obscure the fullscreen notification dialog in Firefox and Thunderbird, enabling spoofing attacks where...

Aug 6, 2024
CVE-2025-36149
6.3

IBM Concert Software versions 1.0.0 through 2.0.0 contain a clickjacking vulnerability (CWE-1021) that allows remote attackers to hijack user clicks. ...

Nov 21, 2025
CVE-2024-54110
6.2

This CVE describes a cross-process screen stack vulnerability in Huawei's UIExtension module that could allow unauthorized access to screen content ac...

Dec 12, 2024
CVE-2026-26000
6.1

This vulnerability in XWiki Platform allows attackers to inject malicious CSS through comments, which can transform the entire wiki interface into a c...

Feb 12, 2026
CVE-2025-52987
6.1

A clickjacking vulnerability in Juniper Networks Paragon Automation web portal allows attackers to embed the interface in malicious frames and trick u...

Jan 15, 2026
CVE-2025-59479
6.1

This vulnerability in CHOCO TEI WATCHER mini (IB-MCT001) allows clickjacking attacks where malicious web content can trick users into performing unint...

Dec 16, 2025
CVE-2025-1494
6.1

This clickjacking vulnerability in IBM Cognos Command Center allows attackers to trick users into clicking malicious elements by overlaying transparen...

Aug 26, 2025
CVE-2025-31138
5.5

This vulnerability in tarteaucitron.js allows attackers with direct access to website source code or CMS plugins to inject malicious CSS values for el...

Apr 7, 2025
CVE-2024-56436
5.5

This CVE describes a cross-process screen stack vulnerability in Huawei's UIExtension module that could allow unauthorized access to screen content ac...

Jan 8, 2025
CVE-2024-54112
5.5

This CVE describes a cross-process screen stack vulnerability in Huawei's UIExtension module that could allow unauthorized access to screen content ac...

Dec 12, 2024
CVE-2024-43084
5.5

This CVE describes a confused deputy vulnerability in Android's visitUris function that allows local information disclosure without user interaction. ...

Nov 13, 2024
CVE-2025-30191
5.4

This CVE describes a redressing attack vulnerability where malicious email content can trick users into performing unintended actions or disclosing se...

Oct 31, 2025
CVE-2024-49796
5.4

IBM ApplinX 11.1 contains a clickjacking vulnerability that allows attackers to hijack user clicks by tricking victims into visiting malicious website...

Feb 6, 2025
CVE-2024-11695
5.4

This vulnerability allows attackers to craft URLs with Arabic script and whitespace characters to hide the true origin of web pages, enabling spoofing...

Nov 26, 2024
CVE-2025-1018
5.3

This vulnerability allows attackers to hide the fullscreen notification in Firefox and Thunderbird by rapidly requesting fullscreen mode, enabling pot...

Feb 4, 2025

About CWE-1021 (CWE-1021)

Our database tracks 68 CVEs classified as CWE-1021, with 3 rated critical and 28 rated high severity. The average CVSS score for CWE-1021 vulnerabilities is 6.4.

External reference: View CWE-1021 on MITRE CWE →

Monitor CWE-1021 Vulnerabilities

Get alerted when new CWE-1021 CVEs affect your infrastructure.

Start Monitoring Free