Skip to main content

CWE archive

CWE-357 CVEs

Programmatic archive

20 CVEs tagged with CWE-3570 Critical, 7 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2026-58597

Published Jul 3, 2026

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-47782

Published May 20, 2026

Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to…

CVSS 4.6 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-47967

Published Sep 16, 2025

Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49587

Published Jun 13, 2025

XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49585

Published Jun 13, 2025

XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right cr…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49583

Published Jun 13, 2025

XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49582

Published Jun 13, 2025

XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer rights, XWiki warns ab…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41904

Published Nov 11, 2022

Element iOS is an iOS Matrix client provided by Element. It is based on MatrixSDK. Prior to version 1.9.7, events encrypted using Megolm for which trust could not be established d…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13521

Published Jan 27, 2020

A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1