← Back
CWE-449

14 CVEs • Abstraction: Base

The UI Performs the Wrong Action

The UI performs the wrong action with respect to the user's request.

JSON object

Loading...

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Jun 17, 2026
Dec 2, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass download protections via a crafted HTML page. (...Show more
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass download protections via a crafted HTML page. (Chromium security severity: Low)Show less
1Linkedin
1Linkedin
Jun 17, 2026
Sep 3, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the...Show more
LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion.Show less
1Microsoft
1Edge
Jun 17, 2026
Aug 12, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
1Microsoft
1Edge Chromium
Jun 17, 2026
Mar 7, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
1Microsoft
1Edge Chromium
Jun 17, 2026
Feb 6, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1Microsoft
1Edge Chromium
Jun 17, 2026
Dec 6, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1Microsoft
1Edge Chromium
Jun 17, 2026
Oct 18, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1Microsoft
1Edge Chromium
Jul 20, 2026
Jun 13, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1Zoom
4Meeting Software Development Kit
RoomsVdi Windows Meeting Clients+1 more
Jun 17, 2026
Feb 14, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
1Zoom
3Meeting Software Development Kit
Video Software Development KitZoom
Jun 17, 2026
Dec 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.
1Zoom
3Meetings
Virtual Desktop InfrastructureZoom
Jun 17, 2026
Nov 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.
1Zoom
3Meeting Software Development Kit
Virtual Desktop InfrastructureZoom
Jun 17, 2026
Sep 12, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
1Zoom
1Zoom
Jun 17, 2026
Aug 8, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access.
1Zoom
3Rooms
Virtual Desktop InfrastructureZoom
Jun 17, 2026
Aug 8, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.