The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
Volume of CVEs assigned to CWE-451 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
308 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-38112HIGH Windows MSHTML Platform Spoofing Vulnerability | Jul 9, 2024 | 7.5 | 93 | YES | NO |
CVE-2024-43461HIGH Windows MSHTML Platform Spoofing Vulnerability | Sep 10, 2024 | 8.8 | 88 | YES | NO |
CVE-2025-9491HIGH Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Aug 26, 2025 | 7.8 | 69 | NO | NO |
CVE-2026-11172HIGH Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium secur | Jun 4, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-53829HIGH OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized | Jun 12, 2026 | 8.0 | 35 | NO | NO |
CVE-2026-11175HIGH Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security se | Jun 4, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-0906CRITICAL Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromiu | Jan 20, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-14114HIGH Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium se | Jun 30, 2026 | 7.5 | 33 | NO | NO |
CVE-2019-25718HIGH Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a sp | Jun 1, 2026 | 8.4 | 33 | NO | NO |
CVE-2026-0096HIGH In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escala | Jun 1, 2026 | 7.8 | 32 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.