CWE-451: CWE-451

73
Total CVEs
4
Critical
7
High
5.7
Avg CVSS

Yearly Trend

2026
14
2025
44
2024
13
2022
1
2021
1

Top Affected Vendors

1 Google 34
2 Microsoft 14
3 Mozilla 9
4 Linecorp 4
5 Github 2
6 Apple 2
7 F5 1
8 Dnnsoftware 1
9 Ibm 1
10 Debian 1

All CWE-451 CVEs (73)

CVE-2026-2634
9.8

This vulnerability in Firefox for iOS allows malicious scripts to desynchronize the address bar from actual web content before a server response arriv...

Feb 24, 2026
CVE-2026-0906
9.8

This vulnerability allows attackers to spoof the URL bar (Omnibox) in Google Chrome on Android, potentially tricking users into believing they're on a...

Jan 20, 2026
CVE-2026-0907
9.8

This vulnerability allows attackers to spoof the user interface in Chrome's Split View mode, potentially tricking users into interacting with maliciou...

Jan 20, 2026
CVE-2025-8043
9.8

This vulnerability involves incorrect URL truncation in Firefox and Thunderbird, which could allow attackers to bypass security controls by manipulati...

Jul 22, 2025
CVE-2024-0750
8.8

A timing vulnerability in Firefox, Firefox ESR, and Thunderbird allows attackers to manipulate popup notification delays, tricking users into granting...

Jan 23, 2024
CVE-2021-41598
8.8

This CVE describes a UI misrepresentation vulnerability in GitHub Enterprise Server where GitHub Apps could gain additional user-level permissions wit...

Jan 25, 2022
CVE-2021-22866
8.8

This CVE describes a UI misrepresentation vulnerability in GitHub Enterprise Server where users granting authorization to GitHub Apps might unknowingl...

May 14, 2021
CVE-2025-9491
7.8

This vulnerability allows attackers to execute arbitrary code on Microsoft Windows systems by tricking users into opening malicious .LNK files. The fl...

Aug 26, 2025
CVE-2024-23708
7.8

This Android vulnerability allows malicious apps to access clipboard content without triggering the normal toast notification, enabling local privileg...

May 7, 2024
CVE-2024-49040
7.5

This vulnerability in Microsoft Exchange Server allows attackers to spoof email addresses, potentially enabling phishing attacks or bypassing email se...

Nov 12, 2024
CVE-2024-38112
7.5

This vulnerability in Windows MSHTML platform allows attackers to spoof content in web pages, potentially tricking users into performing unintended ac...

Jul 9, 2024
CVE-2026-2320
6.5

This vulnerability in Google Chrome allows attackers to trick users into interacting with fake UI elements by convincing them to perform specific gest...

Feb 11, 2026
CVE-2026-2316
6.5

This vulnerability allows attackers to create deceptive UI elements that appear legitimate but perform malicious actions. It affects users of Google C...

Feb 11, 2026
CVE-2026-2318
6.5

This vulnerability allows attackers to perform UI spoofing in Chrome's Picture-in-Picture feature. By convincing users to perform specific UI gestures...

Feb 11, 2026
CVE-2026-0391
6.5

This vulnerability allows an attacker to spoof information in Microsoft Edge for Android's user interface, potentially tricking users into believing t...

Feb 5, 2026
CVE-2025-14744
6.5

This vulnerability allows malicious websites to use Unicode Right-to-Left Override (RTLO) characters to spoof filenames in Firefox for iOS downloads U...

Dec 18, 2025
CVE-2025-46287
6.5

This CVE describes a FaceTime caller ID spoofing vulnerability in Apple operating systems. An attacker can manipulate the caller ID displayed during F...

Dec 12, 2025
CVE-2025-10290
6.5

This vulnerability in Focus for iOS allows attackers to spoof websites by tricking users into opening malicious links through the contextual menu. Whe...

Sep 16, 2025
CVE-2025-43327
6.5

This Safari vulnerability allows malicious websites to spoof the address bar, making users believe they're on a legitimate site when they're actually ...

Sep 15, 2025
CVE-2025-9186
6.5

A spoofing vulnerability in Firefox Focus for Android's address bar component allows attackers to display malicious URLs that appear legitimate. This ...

Aug 19, 2025
CVE-2025-5065
6.5

This vulnerability in Google Chrome's FileSystemAccess API allows attackers to create deceptive user interface elements that trick users into granting...

May 27, 2025
CVE-2025-0435
6.5

This vulnerability allows attackers to create fake UI elements in Chrome for Android that appear legitimate, potentially tricking users into clicking ...

Jan 15, 2025
CVE-2024-38197
6.5

This vulnerability in Microsoft Teams for iOS allows attackers to spoof content, potentially tricking users into interacting with malicious links or i...

Aug 13, 2024
CVE-2024-7529
6.5

This vulnerability allows malicious websites to partially obscure security permission prompts using the date picker interface, potentially tricking us...

Aug 6, 2024
CVE-2023-7011
6.5

This vulnerability in Google Chrome's Picture-in-Picture implementation allows attackers to spoof the URL bar (Omnibox) content via a malicious HTML p...

Jul 16, 2024
CVE-2025-3523
6.4

This vulnerability in Thunderbird email client causes misleading hover text when emails contain multiple attachments with external links. Only the las...

Apr 15, 2025
CVE-2025-11212
6.3

This vulnerability in Google Chrome allows attackers to spoof website domains through crafted HTML pages when users perform specific UI gestures. It a...

Nov 6, 2025
CVE-2025-11213
6.3

This vulnerability allows attackers to spoof website domains in Chrome's address bar on Android devices by tricking users into performing specific UI ...

Nov 6, 2025
CVE-2025-11208
6.3

This vulnerability allows attackers to trick users into interacting with fake UI elements by convincing them to perform specific gestures on a malicio...

Nov 6, 2025
CVE-2025-47963
6.3

This vulnerability in Microsoft Edge (Chromium-based) allows unauthorized attackers to perform spoofing attacks over a network. Attackers can trick us...

Jul 11, 2025
CVE-2025-62224
5.5

This vulnerability in Microsoft Edge for Android allows an attacker to spoof user interface elements, potentially tricking users into revealing sensit...

Jan 7, 2026
CVE-2026-2322
5.4

This vulnerability allows attackers to trick users into interacting with fake UI elements in Chrome's file input interface. Users who visit malicious ...

Feb 11, 2026
CVE-2026-0901
5.4

This vulnerability allows attackers to spoof user interface elements in Chrome on Android, potentially tricking users into interacting with malicious ...

Jan 20, 2026
CVE-2026-0904
5.4

This vulnerability in Google Chrome allows attackers to spoof website domains through manipulated digital credential security interfaces. Users who vi...

Jan 20, 2026
CVE-2025-14020
5.4

LINE for Android versions before 14.20 has a UI spoofing vulnerability where the full-screen security notification disappears when switching apps and ...

Dec 15, 2025
CVE-2025-9865
5.4

This vulnerability allows attackers to spoof website domains in Google Chrome on Android by tricking users into performing specific UI gestures on a m...

Sep 3, 2025
CVE-2024-39730
5.4

This vulnerability in IBM Datacap Navigator allows attackers to perform clickjacking attacks. By tricking users into visiting malicious websites, atta...

Jun 28, 2025
CVE-2025-3072
5.4

This vulnerability allows attackers to spoof UI elements in Chrome's Custom Tabs feature by tricking users into performing specific gestures on a mali...

Apr 2, 2025
CVE-2025-3074
5.4

This vulnerability allows attackers to spoof download UI elements in Google Chrome, tricking users into believing malicious downloads are legitimate. ...

Apr 2, 2025
CVE-2025-21262
5.4

This vulnerability allows an attacker to spoof UI elements in Microsoft Edge, potentially tricking users into interacting with malicious content disgu...

Jan 24, 2025
CVE-2026-1658
5.3

This CVE describes a UI misrepresentation vulnerability in OpenText Directory Services that allows cache poisoning. An attacker can inject manipulated...

Feb 19, 2026
CVE-2025-64667
5.3

This CVE describes a UI spoofing vulnerability in Microsoft Exchange Server where an unauthorized attacker can manipulate the user interface to misrep...

Dec 9, 2025
CVE-2025-8041
5.3

Firefox for Android displayed URLs incorrectly by truncating from the end instead of showing the origin first, potentially hiding malicious domains. T...

Aug 19, 2025
CVE-2025-21253
5.3

Microsoft Edge for iOS and Android contains a spoofing vulnerability that could allow an attacker to display misleading content in the browser interfa...

Feb 6, 2025
CVE-2024-47044
5.3

Multiple Home Gateway/Hikari Denwa routers from NTT East Corporation are vulnerable to insufficient access restrictions on Device Setting pages. Attac...

Sep 26, 2024
CVE-2026-2323
4.3

This vulnerability in Google Chrome's Downloads feature allows attackers to create deceptive download interfaces through malicious HTML pages. Users w...

Feb 11, 2026
CVE-2025-14021
4.3

The LINE iOS app's in-app browser has an address bar spoofing vulnerability that allows attackers to display trusted URLs while running malicious Java...

Dec 15, 2025
CVE-2025-62223
4.3

This vulnerability in Microsoft Edge for iOS allows attackers to spoof user interface elements, potentially tricking users into revealing sensitive in...

Dec 5, 2025
CVE-2025-13082
4.3

This CVE describes a UI misrepresentation vulnerability in Drupal core that allows content spoofing. Attackers can manipulate the user interface to di...

Nov 18, 2025
CVE-2025-13102
4.3

This vulnerability allows attackers to spoof user interface elements in Google Chrome on Android by tricking users into visiting malicious web pages. ...

Nov 14, 2025

About CWE-451 (CWE-451)

Our database tracks 73 CVEs classified as CWE-451, with 4 rated critical and 7 rated high severity. The average CVSS score for CWE-451 vulnerabilities is 5.7.

External reference: View CWE-451 on MITRE CWE →

Monitor CWE-451 Vulnerabilities

Get alerted when new CWE-451 CVEs affect your infrastructure.

Start Monitoring Free