CWE-357
Insufficient UI Warning of Dangerous Operations
Description
The user interface provides a warning to a user regarding dangerous or sensitive operations, but the warning is not noticeable enough to warrant attention.
Hierarchy (View 1000)
CVEs mapped to this weakness (20)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-33054 | Hig | 0.53 | 8.1 | 0.01 | Jul 8, 2025 | Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-43505 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2021-22645 | Hig | 0.51 | 7.8 | 0.02 | Feb 23, 2021 | Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to an attack because the .bip documents display a “load” command, which can be… | ||
| CVE-2019-13521 | Hig | 0.51 | 7.8 | 0.06 | Jan 27, 2020 | A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version… | ||
| CVE-2026-26151 | Hig | 0.46 | 7.1 | 0.01 | Apr 14, 2026 | Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-49587 | Hig | 0.45 | 8.0 | 0.00 | Jun 13, 2025 | XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits and saves that document, the possibly malicious content of that object is output as… | ||
| CVE-2025-49585 | Hig | 0.45 | 8.0 | 0.00 | Jun 13, 2025 | XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right creates an XClass definition in XWiki (requires edit right), and that same document is later edited by… | ||
| CVE-2025-49582 | Hig | 0.45 | 8.0 | 0.01 | Jun 13, 2025 | XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer rights, XWiki warns about the execution of these macros since XWiki 15.9RC1. These required rights analyzers that trigger… | ||
| CVE-2022-41904 | Med | 0.42 | 6.4 | 0.00 | Nov 11, 2022 | Element iOS is an iOS Matrix client provided by Element. It is based on MatrixSDK. Prior to version 1.9.7, events encrypted using Megolm for which trust could not be established did not get decorated accordingly (with warning shields). Therefore a malicious homeserver could… | ||
| CVE-2024-43580 | Med | 0.35 | 5.4 | 0.00 | Oct 17, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-30058 | Med | 0.35 | 5.4 | 0.00 | Jun 13, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-21387 | Med | 0.35 | 5.3 | 0.01 | Jan 26, 2024 | Microsoft Edge for Android Spoofing Vulnerability | ||
| CVE-2025-47967 | Med | 0.31 | 4.7 | 0.00 | Sep 16, 2025 | Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-49054 | Med | 0.28 | 4.3 | 0.01 | Nov 22, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-29057 | Med | 0.28 | 4.3 | 0.01 | Mar 22, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-26188 | Med | 0.28 | 4.3 | 0.01 | Feb 23, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2026-47782 | Low | 0.21 | 3.3 | 0.00 | May 20, 2026 | Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without… | ||
| CVE-2025-49583 | Low | 0.16 | 3.5 | 0.00 | Jun 13, 2025 | XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will be used for notifications. No… | ||
| CVE-2024-21336 | Low | 0.16 | 2.5 | 0.01 | Jan 26, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2026-58597 | Med | 0.00 | 4.3 | 0.00 | Jul 3, 2026 | Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
- risk 0.53cvss 8.1epss 0.01
Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network.
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to an attack because the .bip documents display a “load” command, which can be…
- risk 0.51cvss 7.8epss 0.06
A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version…
- risk 0.46cvss 7.1epss 0.01
Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.
- risk 0.45cvss 8.0epss 0.00
XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits and saves that document, the possibly malicious content of that object is output as…
- risk 0.45cvss 8.0epss 0.00
XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right creates an XClass definition in XWiki (requires edit right), and that same document is later edited by…
- risk 0.45cvss 8.0epss 0.01
XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer rights, XWiki warns about the execution of these macros since XWiki 15.9RC1. These required rights analyzers that trigger…
- risk 0.42cvss 6.4epss 0.00
Element iOS is an iOS Matrix client provided by Element. It is based on MatrixSDK. Prior to version 1.9.7, events encrypted using Megolm for which trust could not be established did not get decorated accordingly (with warning shields). Therefore a malicious homeserver could…
- risk 0.35cvss 5.4epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.35cvss 5.4epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.35cvss 5.3epss 0.01
Microsoft Edge for Android Spoofing Vulnerability
- risk 0.31cvss 4.7epss 0.00
Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.21cvss 3.3epss 0.00
Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without…
- risk 0.16cvss 3.5epss 0.00
XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will be used for notifications. No…
- risk 0.16cvss 2.5epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.00cvss 4.3epss 0.00
Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.