Skip to main content

CWE archive

CWE-1021 CVEs

Programmatic archive

409 CVEs tagged with CWE-10217 Critical, 97 High, 284 Medium, 21 Low, 0 Unrated.

CVE-2026-18534

Published Aug 18, 2026

ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface eleme…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-74978

Published Aug 18, 2026

Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

CVSS 8.1 · High
evidence mentions
5
Buzz score
27.9

CVE-2026-74958

Published Aug 18, 2026

Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

CVSS 7.5 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-74951

Published Aug 18, 2026

Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-44762

Published Aug 11, 2026

SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authen…

CVSS 3.7 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-70608

Published Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow…

CVSS 7.2 · High
evidence mentions
10
Buzz score
29.0

CVE-2026-70600

Published Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill pop…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-70486

Published Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allo…

CVSS 8.2 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-47723

Published Jul 23, 2026

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/`…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-60370

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-16397

Published Jul 21, 2026

Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-40957

Published Jul 15, 2026

o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to poten…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-58595

Published Jul 14, 2026

Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.

CVSS 8.1 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-59791

Published Jul 10, 2026

In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-38979

Published Jul 6, 2026

ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty h…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-14142

Published Jun 30, 2026

Inappropriate implementation in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-14110

Published Jun 30, 2026

Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security sever…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-44727

Published Jun 22, 2026

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origi…

CVSS 9.3 · Critical
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-12348

Published Jun 17, 2026

Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishi…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-10733

Published Jun 11, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticat…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-28577

Published Jun 1, 2026

In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additi…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0061

Published Jun 1, 2026

In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalat…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0036

Published Jun 1, 2026

In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no addit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 409 CVEsPage 1 of 17