Threats Tagged 'cwe-451'
View all threats tagged with 'cwe-451'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-451'
Click on any threat for detailed analysis and mitigation recommendations
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing. Join the discussion | CVE Database V5 | 09/23/2026, 19:02:02 UTC Added: 09/23/2026, 19:48:30 UTC |
0 An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification. Join the discussion | CVE Database V5 | 09/23/2026, 18:55:08 UTC Added: 09/23/2026, 19:03:14 UTC |
0 CVE-2025-52652 is a content spoofing vulnerability in HCL Software MyXalytics that allows an attacker with limited privileges to manipulate displayed content, making it appear as if it originates from a trusted source. This misrepresentation could potentially facilitate phishing or data theft. The vulnerability has a low CVSS score of 3.5, indicating limited impact. No affected versions or patch information are provided. Join the discussion | CVE Database V5 | 09/07/2026, 10:37:31 UTC Added: 09/07/2026, 10:52:40 UTC |
0 A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Join the discussion | CVE Database V5 | 09/02/2026, 15:40:53 UTC Added: 09/02/2026, 15:53:04 UTC |
0 Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures. Join the discussion | CVE Database V5 | 08/13/2026, 07:00:23 UTC Added: 08/13/2026, 07:11:54 UTC |
0 A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site. Join the discussion | GCVE Database | 08/06/2026, 16:32:39 UTC Added: 08/07/2026, 05:56:53 UTC |
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via malicious network traffic. (Chromium security severity: Medium) Join the discussion | GCVE Database | 07/30/2026, 03:31:14 UTC Added: 08/01/2026, 08:14:19 UTC |
Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Join the discussion | GCVE Database | 07/30/2026, 03:31:13 UTC Added: 07/31/2026, 19:31:06 UTC |
Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low) Join the discussion | GCVE Database | 07/30/2026, 00:26:10 UTC Added: 07/30/2026, 05:45:50 UTC |
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Join the discussion | GCVE Database | 07/30/2026, 00:26:08 UTC Added: 07/30/2026, 05:45:51 UTC |
Showing 1 to 10 of 77 results