Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Pybbs MEDIUM 6.1
CVE-2025-8813

A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as problematic. This vulnerability affects the function changeLanguage of th…

Fix: after 6.0.0
Fix from $1,600 2025-08-10
Astro MEDIUM 6.1
CVE-2025-54793

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash…

Fix: 5.12.7+
Fix from $1,600 2025-08-08
Operational Decision Manager HIGH 7.4
CVE-2025-2824

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an…

Mitigation only
Fix from $1,950 2025-08-01
Unclassified MEDIUM 6.3
CVE-2024-34328

An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.

Mitigation only
Fix from $1,600 2025-07-31
Docker Heimdall CRITICAL 9.8
CVE-2025-50578

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Refer…

Mitigation only
Fix from $2,300 2025-07-30
Glpi MEDIUM 6.1
CVE-2025-52897

GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to atte…

Fix: 10.0.19+
Fix from $1,600 2025-07-30
Unclassified MEDIUM 5.1
CVE-2025-54414

Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to protect upstream resources fr…

Patch available
Fix from $1,600 2025-07-26
Koa MEDIUM 6.1
CVE-2025-8129

A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.j…

Fix: 2.16.2+
Fix from $1,600 2025-07-25
Unclassified MEDIUM 5.4
CVE-2025-44109

A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.

Mitigation only
Fix from $1,600 2025-07-23
Unclassified MEDIUM 5.4
CVE-2025-50477

A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.

Mitigation only
Fix from $1,600 2025-07-23
Publiccms MEDIUM 6.1
CVE-2025-7953

A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS up to 5.202506.a. This issue affects some unknown processin…

Fix: 5.202506.b+
Fix from $1,600 2025-07-22
Publiccms MEDIUM 6.1
CVE-2025-7949

A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerability is an unknown fu…

Fix: 5.202506.b+
Fix from $1,600 2025-07-22
Unclassified HIGH 7.6
CVE-2025-6023EPSS 39%

An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in G…

Mitigation only
Fix from $1,950 2025-07-18
Application Express CRITICAL 9.0
CVE-2025-50067

Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5.…

Patch available
Fix from $2,300 2025-07-15
Wegia MEDIUM 6.1
CVE-2025-53821

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirect vulnerability exists in the…

Fix: 3.4.5+
Fix from $1,600 2025-07-14
Unclassified MEDIUM 6.1
CVE-2025-42981

Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malici…

Mitigation only
Fix from $1,600 2025-07-08
Unclassified MEDIUM 6.1
CVE-2025-42985

Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts…

Mitigation only
Fix from $1,600 2025-07-08
Gnuboard MEDIUM 6.1
CVE-2024-37656

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter veri…

No fix yet
Fix from $1,600 2025-07-07
Gnuboard MEDIUM 6.1
CVE-2024-37657

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component.

Patch available
Fix from $1,600 2025-07-07
Gnuboard MEDIUM 6.1
CVE-2024-37658

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.

Patch available
Fix from $1,600 2025-07-07
Ai Engine HIGH 8.0
CVE-2025-6238

The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect…

Patch available
Fix from $1,950 2025-07-04
N8n MEDIUM 5.4
CVE-2025-49592

n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be red…

Fix: 1.98.0+
Fix from $1,600 2025-06-26
Xxl Sso MEDIUM 6.1
CVE-2025-6701

A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-sso 1.1.0. This issue affects some unknown processing of the file…

No fix yet
Fix from $1,600 2025-06-26
Kibana MEDIUM 5.4
CVE-2025-25012

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via …

Fix: 7.17.29 / 8.17.8+
Fix from $1,600 2025-06-25
Process Mining HIGH 8.2
CVE-2025-36016

IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vi…

Mitigation only
Fix from $1,950 2025-06-21
Fastgpt MEDIUM 6.1
CVE-2025-52552

FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based…

Fix: 4.9.12+
Fix from $1,600 2025-06-21
Covid19 Testing Management System MEDIUM 6.1
CVE-2025-6286

A vulnerability classified as problematic has been found in PHPGurukul COVID19 Testing Management System 2021. Affected is an unknown function of the…

Mitigation only
Fix from $1,600 2025-06-19
Urllib3 MEDIUM 6.1
CVE-2025-50182

urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browse…

Fix: 2.5.0+
Fix from $1,600 2025-06-19
Urllib3 MEDIUM 6.1
CVE-2025-50181

urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a Po…

Fix: 2.5.0+
Fix from $1,600 2025-06-19
M Files Mobile MEDIUM 5.4
CVE-2025-2091

An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously craf…

Fix: 25.6.0+
Fix from $1,600 2025-06-16