Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
Microsoft Bing App for IOS Spoofing Vulnerability
In JetBrains YouTrack before 2026
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
Address Bar Spoofing in Arc Search for Android (window.open race condition)
Improper Restriction of Rendered UI Layers or Frames in GitLab
HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security Policy
Besen BS20 EV Charging Station Firmware Version Check ui layer
HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured
Improper Restriction of Rendered UI Layers or Frames in GitLab
Address bar spoofing risk in ArcSearch on Android
HCL Nomad server on Domino is affected by a missing default frame-ancestors directive
Lack of protection mechanisms against Clickjacking attacks
Tenda F3 Clickjacking in Web Management Interface
XWiki Platform affected by click-jacking through CSS injection in comments
Dokploy has a clickjacking vulnerability - Missing X-Frame-Options and CSP frame-ancestors headers
WeGIA Clickjacking Vulnerability
CVE-2025-15032: Increased Spoofing risk; custom new window missing about:blank
Paragon Automation: A clickjacking vulnerability in the web server configuration has been addressed
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted we...
Showing 1 - 20 of 1,000+ results