Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Taguette MEDIUM 6.1
CVE-2025-67502

Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitra…

Fix: 1.5.2+
Fix from $1,600 2025-12-10
Central Dogma MEDIUM 6.1
CVE-2025-11222

Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially …

Fix: 0.78.0+
Fix from $1,600 2025-12-04
Splunk MEDIUM 5.4
CVE-2025-20382

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.10, 10.0.2503.8, and 9.3.241…

Fix: 9.2.10 / 9.3.8+
Fix from $1,600 2025-12-03
Jumpserver MEDIUM 6.1
CVE-2025-58044

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// end…

Fix: 3.10.19 / 4.10.5+
Fix from $1,600 2025-12-01
Unclassified MEDIUM 6.1
CVE-2025-13819

Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to arbitrary external websites v…

Mitigation only
Fix from $1,600 2025-12-01
Unclassified HIGH 8.6
CVE-2024-8527

Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user …

Mitigation only
Fix from $1,950 2025-11-19
Backdrop Cms MEDIUM 6.1
CVE-2025-63828

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redi…

No fix yet
Fix from $1,600 2025-11-18
Chrome MEDIUM 6.3
CVE-2024-13983

Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR…

Fix: 136.0.7103.59+
Fix from $1,600 2025-11-14
Unclassified MEDIUM 5.1
CVE-2025-64716

Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. Prior to version 1.2…

Patch available
Fix from $1,600 2025-11-13
Splunk MEDIUM 6.1
CVE-2025-20378

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9.3.2411.111, and 9.3.2408.121…

Fix: 9.2.9 / 9.3.7+
Fix from $1,600 2025-11-12
Unclassified MEDIUM 6.1
CVE-2025-42924

SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected t…

Mitigation only
Fix from $1,600 2025-11-11
Business Connector MEDIUM 6.1
CVE-2025-42893

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victi…

Mitigation only
Fix from $1,600 2025-11-11
Onlook MEDIUM 6.5
CVE-2025-63784

An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web appli…

No fix yet
Fix from $1,600 2025-11-07
Unclassified MEDIUM 6.1
CVE-2025-12789

A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri para…

Mitigation only
Fix from $1,600 2025-11-07
Digital Experience Platform MEDIUM 6.1
CVE-2025-62266

By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 20…

Fix: 7.4.3.110+
Fix from $1,600 2025-10-30
Movary MEDIUM 6.1
CVE-2025-64115

Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header valu…

Fix: 0.69.0+
Fix from $1,600 2025-10-30
Movary MEDIUM 6.1
CVE-2025-64116

Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without…

Fix: 0.69.0+
Fix from $1,600 2025-10-30
Unclassified MEDIUM 6.1
CVE-2025-50736

An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect us…

Mitigation only
Fix from $1,600 2025-10-30
Zitadel HIGH 8.8
CVE-2025-64101

Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password r…

Fix: 2.71.18 / 3.4.3+
Fix from $1,950 2025-10-29
Digital Experience Platform MEDIUM 6.1
CVE-2025-62253

Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q4.…

Fix: 7.3 / 7.4.3.98+
Fix from $1,600 2025-10-27
Unclassified HIGH 8.1
CVE-2025-62716

Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_path query parameter allows att…

Mitigation only
Fix from $1,950 2025-10-24
Unclassified MEDIUM 5.1
CVE-2025-10355

Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious URL using a manipulated redirec…

Mitigation only
Fix from $1,600 2025-10-23
Scripting MEDIUM 6.1
CVE-2025-61753

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3…

Fix: after 12.2.14
Fix from $1,600 2025-10-21
Koa MEDIUM 6.1
CVE-2025-62595

Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE…

Fix: 3.0.3+
Fix from $1,600 2025-10-21
Unclassified HIGH 8.8
CVE-2025-62428

Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host Header Injection in the /regi…

Mitigation only
Fix from $1,950 2025-10-16
Frappe MEDIUM 6.1
CVE-2025-62407

Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the l…

Fix: 14.98.0 / 15.83.0+
Fix from $1,600 2025-10-16
Fortios MEDIUM 6.1
CVE-2025-47890

An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Fo…

Fix: 7.4.9 / 7.6.4+
Fix from $1,600 2025-10-14
Wegia MEDIUM 6.1
CVE-2025-62361

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open Redirect vulnerability was id…

Fix: 3.5.0+
Fix from $1,600 2025-10-13
Project Center MEDIUM 6.1
CVE-2025-35059

Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.

Fix: 2024.1+
Fix from $1,600 2025-10-09
Unclassified MEDIUM 5.5
CVE-2025-0608

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forceful Browsing. This issue af…

Mitigation only
Fix from $1,600 2025-10-06