Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Wegia MEDIUM 6.1
CVE-2025-61606

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identi…

Fix: 3.5.0+
Fix from $1,600 2025-10-02
Secure Access MEDIUM 6.1
CVE-2025-54088

CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims t…

Fix: 14.10+
Fix from $1,600 2025-10-02
Business Hub HIGH 7.2
CVE-2025-11240

An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legi…

Fix: 1.16.0+
Fix from $1,950 2025-10-02
Weblate MEDIUM 6.1
CVE-2025-61587

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblat…

Fix: 5.13.3+
Fix from $1,600 2025-10-01
Unclassified HIGH 7.5
CVE-2024-55017

Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to intercept auth…

Mitigation only
Fix from $1,950 2025-09-30
Portal For Arcgis MEDIUM 6.1
CVE-2025-57878

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a …

Patch available
Fix from $1,600 2025-09-29
Portal For Arcgis MEDIUM 6.1
CVE-2025-57879

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a …

Patch available
Fix from $1,600 2025-09-29
Portal For Arcgis MEDIUM 6.1
CVE-2025-57872

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a …

Patch available
Fix from $1,600 2025-09-29
Mattermost Server MEDIUM 5.4
CVE-2025-9072

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft …

Fix: 10.5.10 / 10.9.5+
Fix from $1,600 2025-09-15
Mattermost Server MEDIUM 6.1
CVE-2025-9084

Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted …

Fix: 10.5.10+
Fix from $1,600 2025-09-15
Digital Experience Platform MEDIUM 6.1
CVE-2025-43795

Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA th…

Fix: 7.3 / 7.4.3.102+
Fix from $1,600 2025-09-12
Element Plus MEDIUM 6.4
CVE-2025-57665

Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction…

Fix: after 2.10.6
Fix from $1,600 2025-09-09
TYPO3 MEDIUM 6.1
CVE-2025-59013

An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.…

Fix: 9.5.55 / 10.4.54+
Fix from $1,600 2025-09-09
Webex Meetings MEDIUM 6.1
CVE-2025-20291

A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untru…

Mitigation only
Fix from $1,600 2025-09-03
Unclassified MEDIUM 6.3
CVE-2024-12924

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing. This issue affects QR Menü…

Mitigation only
Fix from $1,600 2025-09-01
Unclassified HIGH 7.1
CVE-2025-20317

A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unaut…

Mitigation only
Fix from $1,950 2025-08-27
Cognos Command Center CRITICAL 9.3
CVE-2025-2697

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi…

Mitigation only
Fix from $2,300 2025-08-26
Selectzero MEDIUM 6.5
CVE-2025-52219

SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to create arb…

Fix: 2025.5.2+
Fix from $1,600 2025-08-26
Digital Experience Platform MEDIUM 6.1
CVE-2025-43767

Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 th…

Fix: 7.4.3.132 / 2024.Q1.13+
Fix from $1,600 2025-08-23
Audiobookshelf HIGH 8.8
CVE-2025-57800

Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect …

Fix: 2.28.0+
Fix from $1,950 2025-08-22
Reolink MEDIUM 5.3
CVE-2025-55624

An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-public com…

No fix yet
Fix from $1,600 2025-08-22
Reolink MEDIUM 6.3
CVE-2025-55625

An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is …

No fix yet
Fix from $1,600 2025-08-22
Unclassified MEDIUM 5.1
CVE-2025-55751

OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the University of Central Florida. A…

Patch available
Fix from $1,600 2025-08-20
Unclassified MEDIUM 6.5
CVE-2025-7777

The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirec…

Mitigation only
Fix from $1,600 2025-08-20
Firefox CRITICAL 9.8
CVE-2025-55031

Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …

Fix: 142.0+
Fix from $2,300 2025-08-19
Firefox Focus MEDIUM 6.1
CVE-2025-55032

Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowin…

Fix: 142.0+
Fix from $1,600 2025-08-19
Firefox MEDIUM 5.4
CVE-2025-54144

The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal p…

Fix: 141.0+
Fix from $1,600 2025-08-19
Firefox CRITICAL 9.1
CVE-2025-54145

The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text UR…

Fix: 141.0+
Fix from $2,300 2025-08-19
Unclassified MEDIUM 5.5
CVE-2025-55207

Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerability in a subset of Astro depl…

Patch available
Fix from $1,600 2025-08-15
Unclassified MEDIUM 5.1
CVE-2025-55166

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method only searches for lower-case…

Patch available
Fix from $1,600 2025-08-12