Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Ishare Maps MEDIUM 6.1
CVE-2025-6089

A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability affects unknown code of the fi…

Mitigation only
Fix from $1,600 2025-06-15
Api Manager MEDIUM 6.1
CVE-2024-1440

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint …

Mitigation only
Fix from $1,600 2025-06-02
Zitadel HIGH 8.8
CVE-2025-48936

Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the passw…

Fix: 2.70.12 / 2.71.11+
Fix from $1,950 2025-05-30
Unclassified MEDIUM 5.4
CVE-2025-5256

SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an att…

Mitigation only
Fix from $1,600 2025-05-28
Unclassified MEDIUM 6.1
CVE-2025-23183

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

No fix yet
Fix from $1,600 2025-05-22
Grafana MEDIUM 6.1
CVE-2025-4123EPSS 98%

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to …

Fix: 10.4.18 / 11.2.9+
Fix from $1,600 2025-05-22
Unclassified MEDIUM 6.1
CVE-2024-12561

The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0…

Mitigation only
Fix from $1,600 2025-05-21
Teamcity MEDIUM 6.1
CVE-2025-47854

In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page

Fix: 2025.03.2+
Fix from $1,600 2025-05-20
Flask Appbuilder MEDIUM 6.1
CVE-2025-32962

Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated a…

Fix: 4.6.2+
Fix from $1,600 2025-05-16
Mail Server MEDIUM 6.1
CVE-2025-40630

Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domai…

Mitigation only
Fix from $1,600 2025-05-16
Horilla MEDIUM 6.1
CVE-2025-47789

Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attacker can craft a Horilla URL t…

Fix: 1.3.1+
Fix from $1,600 2025-05-15
Wp Content Copy Protection \& No Right Click MEDIUM 6.1
CVE-2024-6690

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

Fix: 15.3+
Fix from $1,600 2025-05-15
Payment Gateway For Telcell MEDIUM 6.1
CVE-2023-6786

The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, lead…

Fix: 2.0.4+
Fix from $1,600 2025-05-15
Supplier Relationship Management MEDIUM 6.1
CVE-2025-30010

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which…

Mitigation only
Fix from $1,600 2025-05-13
Unclassified HIGH 7.1
CVE-2025-40846

Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing attackers to redirect users t…

Mitigation only
Fix from $1,950 2025-05-08
Summaly MEDIUM 6.1
CVE-2025-46553

@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `…

Fix: 5.2.1+
Fix from $1,600 2025-05-05
Workers Oauth Provider MEDIUM 6.1
CVE-2025-4143

The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly valid…

Patch available
Fix from $1,600 2025-05-01
Firefox Focus MEDIUM 6.1
CVE-2025-3859

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick u…

Fix: 138.0+
Fix from $1,600 2025-04-30
Xwiki MEDIUM 6.1
CVE-2025-32970

XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to …

Fix: 15.10.13 / 16.4.4+
Fix from $1,600 2025-04-30
Unclassified MEDIUM 5.0
CVE-2025-2068

An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.

Mitigation only
Fix from $1,600 2025-04-25
Security Awareness Training MEDIUM 6.1
CVE-2020-36845

The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before …

Fix: 2020-01-10+
Fix from $1,600 2025-04-20
Thunderbird MEDIUM 6.3
CVE-2025-3522

Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thu…

Fix: 128.9.2 / 137.0.2+
Fix from $1,600 2025-04-15
Autogpt Platform HIGH 8.6
CVE-2025-31491

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…

Fix: 0.6.1+
Fix from $1,950 2025-04-15
Iksoris MEDIUM 6.1
CVE-2024-49706

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parame…

Fix: 79.0+
Fix from $1,600 2025-04-14
Unclassified MEDIUM 6.1
CVE-2025-3433

The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.1. This is due to insuf…

Mitigation only
Fix from $1,600 2025-04-08
Debian Linux HIGH 7.4
CVE-2025-3155EPSS 13%

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious …

No fix yet
Fix from $1,950 2025-04-03
Safari HIGH 8.1
CVE-2025-24180

The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.…

Fix: 2.3 / 15.4+
Fix from $1,950 2025-03-31
Ejbca MEDIUM 6.1
CVE-2025-3027

The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, t…

Fix: 9.1+
Fix from $1,600 2025-03-31
Unity Operating Environment HIGH 8.8
CVE-2025-24381

Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker wi…

Fix: 5.5.0.0.5.259+
Fix from $1,950 2025-03-28
Icinga Web 2 MEDIUM 6.1
CVE-2025-30164

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…

Fix: 2.11.5 / 2.12.3+
Fix from $1,600 2025-03-26