CWE-1021

CWE-1021 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-1021, highest CVSS first.

  1. CRITICAL 9.6CVE-2026-84388

    A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.2CVE-2026-70486public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the applicat…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.4CVE-2026-71177

    Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading t…

    policy manager for secure connect gateway

    AI risk analysis on Exploit-DB.ai →