Weaknesses of type CWE-451

389 results

Representação enganosa de informação crítica na interface

A aplicação apresenta informações de segurança ou críticas de forma enganosa, confusa ou oculta na interface. Um usuário não consegue identificar claramente riscos, avisos de segurança ou status autêntico da aplicação, levando a decisões incorretas. Exemplos comuns: cadeado falso em phishing, avisos de segurança com estilo igual a anúncios legítimos, ou status de autenticação não evidente.

Example

Um site de phishing usa CSS para desenhar um ícone de cadeado genuíno na barra de endereço, ou oculta avisos críticos de certificado inválido em texto pequeno e cor opaca. Outro caso: app mobile que não deixa claro quando uma conexão está criptografada versus em texto plano.

How to mitigate

Garanta que informações críticas (status de autenticação, certificados válidos, avisos de segurança) sejam apresentadas de forma proeminente, inambígua e não-adulterável pela aplicação. Use padrões do SO para indicadores de segurança, testes de usabilidade para validar clareza de avisos, e desconfie de interfaces que ocultam ou disfarçam estado de segurança.

CVE-2026-74975MEDIUMSpoofing issue in the Downloads component in Firefox for AndroidEPSS 0.2%CVE-2026-60658HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.1%CVE-2026-3925MEDIUMIncorrect security UI in LookalikeChecks in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofingEPSS 0.1%CVE-2025-52652LOWHCL MyXalytics is affected by multiple security vulnerabilities.EPSS 0.1%CVE-2026-11232MEDIUMInappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicEPSS 0.1%CVE-2026-18009MEDIUMInsufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spooEPSS 0.1%CVE-2026-18010MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicEPSS 0.1%CVE-2026-18008MEDIUMInappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via maliciEPSS 0.1%CVE-2026-87624MEDIUMUI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the reEPSS 0.1%CVE-2026-8584MEDIUMInappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendEPSS 0.1%CVE-2026-8565MEDIUMInappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to instalEPSS 0.1%CVE-2026-84137CRITICALSpoofing issue in the DOM: Core & HTML componentEPSS 0.1%CVE-2026-3928MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a EPSS 0.1%CVE-2026-35371LOWuutils coreutils id Misleading Identity Reporting in Pretty Print ModeEPSS 0.1%CVE-2026-18622MEDIUMFoxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as validEPSS 0.1%CVE-2026-8006MEDIUMInsufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a maEPSS 0.1%CVE-2026-8008MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicEPSS 0.1%CVE-2026-17998MEDIUMIncorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious EPSS 0.1%CVE-2019-25718HIGHDräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode BypassEPSS 0.1%CVE-2026-32303HIGHCryptomator: Tampered vault configuration allows MITM attack on Hub APIEPSS 0.1%