CWE-451: CWE-451

73
Total CVEs
4
Critical
7
High
5.7
Avg CVSS

Yearly Trend

2026
14
2025
44
2024
13
2022
1
2021
1

Top Affected Vendors

1 Google 34
2 Microsoft 14
3 Mozilla 9
4 Linecorp 4
5 Github 2
6 Apple 2
7 F5 1
8 Dnnsoftware 1
9 Ibm 1
10 Debian 1

All CWE-451 CVEs (73)

CVE-2025-13107
4.3

This vulnerability allows attackers to create deceptive UI elements that appear legitimate but are actually malicious, enabling phishing or clickjacki...

Nov 14, 2025
CVE-2024-13178
4.3

This vulnerability allows attackers to create fake fullscreen interfaces that mimic legitimate websites, tricking users into interacting with maliciou...

Nov 14, 2025
CVE-2024-7021
4.3

This vulnerability allows attackers to create fake autofill UI elements in Chrome that appear legitimate, tricking users into entering sensitive infor...

Nov 14, 2025
CVE-2024-11919
4.3

This vulnerability allows attackers to create deceptive user interfaces in Google Chrome on Android through malicious web pages. It affects Android us...

Nov 14, 2025
CVE-2025-12911
4.3

This vulnerability in Google Chrome allows attackers to create deceptive UI elements that mimic legitimate browser permissions prompts. Users running ...

Nov 8, 2025
CVE-2024-6429
4.3

This content spoofing vulnerability in WSO2 products allows attackers to inject arbitrary content into error messages displayed in the browser UI. By ...

Sep 23, 2025
CVE-2025-49755
4.3

This CVE describes a UI spoofing vulnerability in Microsoft Edge for Android where an attacker can manipulate the browser interface to display mislead...

Aug 12, 2025
CVE-2025-8583
4.3

This vulnerability in Google Chrome allows attackers to create malicious web pages that spoof legitimate UI elements like permission prompts or securi...

Aug 7, 2025
CVE-2025-32371
4.3

CVE-2025-32371 is a content spoofing vulnerability in DNN (DotNetNuke) CMS where attackers can craft URLs to the ImageHandler to display arbitrary tex...

Apr 9, 2025
CVE-2025-0729
4.3

This CVE describes a clickjacking vulnerability in TP-Link TL-SG108E network switches. Attackers can trick users into clicking hidden interface elemen...

Jan 27, 2025
CVE-2025-0446
4.3

This vulnerability allows malicious Chrome extensions to spoof user interface elements through specific UI gestures. Users who install crafted extensi...

Jan 15, 2025
CVE-2023-7281
4.3

This vulnerability allows attackers to create deceptive UI elements that appear legitimate but are actually malicious. It affects users of Google Chro...

Sep 23, 2024
CVE-2024-7020
4.3

This vulnerability allows attackers to create malicious web pages that can spoof Chrome's autofill interface, potentially tricking users into revealin...

Sep 23, 2024
CVE-2024-8909
4.3

This vulnerability allows attackers to create deceptive UI elements in Google Chrome on iOS, potentially tricking users into clicking malicious links ...

Sep 17, 2024
CVE-2024-6999
4.3

This vulnerability in Google Chrome's FedCM (Federated Credential Management) implementation allows attackers to spoof UI elements through crafted HTM...

Aug 6, 2024
CVE-2024-38093
4.3

This vulnerability in Microsoft Edge allows attackers to spoof UI elements, potentially tricking users into interacting with malicious content. It aff...

Jun 20, 2024
CVE-2025-12729
4.2

This vulnerability allows attackers to spoof UI elements in Chrome's address bar (Omnibox) on Android devices by tricking users into performing specif...

Nov 10, 2025
CVE-2025-12446
4.2

This vulnerability allows attackers to spoof the browser UI in Google Chrome's SplitView feature by tricking users into performing specific gestures o...

Nov 10, 2025
CVE-2025-12728
4.2

This vulnerability allows attackers to spoof UI elements in Chrome's address bar (Omnibox) on Android devices by tricking users into performing specif...

Nov 10, 2025
CVE-2025-14019
3.4

LINE for Android versions 13.8 through 15.5 contains a UI spoofing vulnerability in its in-app browser. Attackers can obscure full-screen warning prom...

Dec 15, 2025
CVE-2026-20732
3.1

This vulnerability in an undisclosed BIG-IP Configuration utility page allows attackers to spoof error messages, potentially tricking users into perfo...

Feb 4, 2026
CVE-2025-65046
3.1

This vulnerability in Microsoft Edge allows attackers to spoof content in the browser's address bar or UI elements, potentially tricking users into be...

Dec 18, 2025
CVE-2025-14023
3.1

This vulnerability in LINE for iOS allows attackers to spoof the user interface, creating confusion about whether displayed pages or interactive eleme...

Dec 15, 2025

About CWE-451 (CWE-451)

Our database tracks 73 CVEs classified as CWE-451, with 4 rated critical and 7 rated high severity. The average CVSS score for CWE-451 vulnerabilities is 5.7.

External reference: View CWE-451 on MITRE CWE →

Monitor CWE-451 Vulnerabilities

Get alerted when new CWE-451 CVEs affect your infrastructure.

Start Monitoring Free