VYPR

CWE-357

Insufficient UI Warning of Dangerous Operations

BaseDraft

Description

The user interface provides a warning to a user regarding dangerous or sensitive operations, but the warning is not noticeable enough to warrant attention.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (20)

  • CVE-2025-33054HigJul 8, 2025
    risk 0.53cvss 8.1epss 0.01

    Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2024-43505HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2021-22645HigFeb 23, 2021
    risk 0.51cvss 7.8epss 0.02

    Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to an attack because the .bip documents display a “load” command, which can be…

  • CVE-2019-13521HigJan 27, 2020
    risk 0.51cvss 7.8epss 0.06

    A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version…

  • CVE-2026-26151HigApr 14, 2026
    risk 0.46cvss 7.1epss 0.01

    Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-49587HigJun 13, 2025
    risk 0.45cvss 8.0epss 0.00

    XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits and saves that document, the possibly malicious content of that object is output as…

  • CVE-2025-49585HigJun 13, 2025
    risk 0.45cvss 8.0epss 0.00

    XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right creates an XClass definition in XWiki (requires edit right), and that same document is later edited by…

  • CVE-2025-49582HigJun 13, 2025
    risk 0.45cvss 8.0epss 0.01

    XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer rights, XWiki warns about the execution of these macros since XWiki 15.9RC1. These required rights analyzers that trigger…

  • CVE-2022-41904MedNov 11, 2022
    risk 0.42cvss 6.4epss 0.00

    Element iOS is an iOS Matrix client provided by Element. It is based on MatrixSDK. Prior to version 1.9.7, events encrypted using Megolm for which trust could not be established did not get decorated accordingly (with warning shields). Therefore a malicious homeserver could…

  • CVE-2024-43580MedOct 17, 2024
    risk 0.35cvss 5.4epss 0.00

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2024-30058MedJun 13, 2024
    risk 0.35cvss 5.4epss 0.00

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2024-21387MedJan 26, 2024
    risk 0.35cvss 5.3epss 0.01

    Microsoft Edge for Android Spoofing Vulnerability

  • CVE-2025-47967MedSep 16, 2025
    risk 0.31cvss 4.7epss 0.00

    Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2024-49054MedNov 22, 2024
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2024-29057MedMar 22, 2024
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2024-26188MedFeb 23, 2024
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2026-47782LowMay 20, 2026
    risk 0.21cvss 3.3epss 0.00

    Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without…

  • CVE-2025-49583LowJun 13, 2025
    risk 0.16cvss 3.5epss 0.00

    XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will be used for notifications. No…

  • CVE-2024-21336LowJan 26, 2024
    risk 0.16cvss 2.5epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2026-58597MedJul 3, 2026
    risk 0.00cvss 4.3epss 0.00

    Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.