CWE-1021
CWE-1021 · 3 records · 1 with a public proof-of-concept
Records the NVD classes under CWE-1021, highest CVSS first.
- CRITICAL 9.6CVE-2026-84388
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
- HIGH 8.2CVE-2026-70486public PoC
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the applicat…
- MEDIUM 5.4CVE-2026-71177
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading t…
policy manager for secure connect gateway