VYPR

CWE-356

Product UI does not Warn User of Unsafe Actions

BaseIncomplete

Description

The product's user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.

Product systems should warn users that a potentially dangerous action may occur if the user proceeds. For example, if the user downloads a file from an unknown source and attempts to execute the file on their machine, then the application's GUI can indicate that the file is unsafe.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (32)

page 2 of 2
  • CVE-2025-31334MedApr 3, 2025
    risk 0.44cvss 6.8epss 0.01

    Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary…

  • CVE-2026-25805MedFeb 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the tool was being invoked, which parameters were used. Thus, maybe unwanted or even malicious values…

  • CVE-2025-0092MedAug 26, 2025
    risk 0.42cvss 6.5epss 0.00

    In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2018-10595MedMay 24, 2018
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in loss or corruption of data.

  • CVE-2024-2609MedMar 19, 2024
    risk 0.40cvss 6.1epss 0.01

    The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

  • CVE-2025-58335MedAug 28, 2025
    risk 0.36cvss 5.5epss 0.00

    In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function

  • CVE-2018-10593MedMay 24, 2018
    risk 0.36cvss 5.6epss 0.00

    A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may…

  • CVE-2024-4187MedJul 31, 2024
    risk 0.35cvss 5.4epss 0.00

    Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.

  • CVE-2024-30057MedJun 13, 2024
    risk 0.35cvss 5.4epss 0.00

    Microsoft Edge for iOS Spoofing Vulnerability

  • CVE-2024-3044MedMay 14, 2024
    risk 0.35cvss 6.5epss 0.01

    Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed…

  • CVE-2019-17151MedJan 7, 2020
    risk 0.35cvss 5.4epss 0.01

    This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent WeChat Prior to 7.0.9. User interaction is required to exploit this vulnerability in that the target must be within a chat session together with the attacker.…

  • CVE-2022-39362HigOct 26, 2022
    risk 0.00cvss 8.8epss 0.01

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries are auto-executed, which could pose a possible attack vector. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7,…