Vulnerabilities (CVE)

Filtered by CWE-451
Total 385 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-84137 1 Mozilla 2 Firefox, Thunderbird 2026-09-03 N/A 4.3 MEDIUM
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84356 1 Google 1 Chrome 2026-09-03 N/A 4.3 MEDIUM
UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-81267 1 Mozilla 1 Firefox Mobile 2026-09-03 N/A 5.4 MEDIUM
A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.
CVE-2026-78974 1 Google 1 Chrome 2026-08-31 N/A 5.4 MEDIUM
UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79108 1 Google 1 Chrome 2026-08-31 N/A 6.5 MEDIUM
UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79011 1 Google 1 Chrome 2026-08-31 N/A 8.1 HIGH
UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)
CVE-2026-78912 1 Google 1 Chrome 2026-08-28 N/A 5.4 MEDIUM
UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-18487 2026-08-28 N/A 5.4 MEDIUM
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
CVE-2026-79009 1 Google 1 Chrome 2026-08-28 N/A 4.3 MEDIUM
UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79022 1 Google 1 Chrome 2026-08-28 N/A 4.3 MEDIUM
UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79098 1 Google 1 Chrome 2026-08-28 N/A 4.3 MEDIUM
UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79173 1 Google 1 Chrome 2026-08-28 N/A 5.4 MEDIUM
UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79180 1 Google 2 Android, Chrome 2026-08-28 N/A 5.4 MEDIUM
UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79204 2 Apple, Google 2 Macos, Chrome 2026-08-28 N/A 5.4 MEDIUM
UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79250 1 Google 1 Chrome 2026-08-28 N/A 5.4 MEDIUM
UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79283 1 Google 1 Chrome 2026-08-28 N/A 5.4 MEDIUM
UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79233 1 Google 2 Android, Chrome 2026-08-27 N/A 4.3 MEDIUM
UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79176 1 Google 1 Chrome 2026-08-27 N/A 6.5 MEDIUM
UI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-79284 2 Apple, Google 2 Macos, Chrome 2026-08-27 N/A 4.3 MEDIUM
UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-74975 1 Mozilla 1 Firefox Mobile 2026-08-25 N/A 5.4 MEDIUM
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.