Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Druid MEDIUM 5.4
CVE-2025-27888

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…

Fix: 31.0.2+
Fix from $1,600 2025-03-20
Llava MEDIUM 6.1
CVE-2024-9308

An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrar…

No fix yet
Fix from $1,600 2025-03-20
Gradio MEDIUM 6.1
CVE-2024-8021

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicio…

No fix yet
Fix from $1,600 2025-03-20
Stable Diffusion Webui MEDIUM 6.1
CVE-2024-11044

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to a…

No fix yet
Fix from $1,600 2025-03-20
Fastchat MEDIUM 6.1
CVE-2024-10908

An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites vi…

No fix yet
Fix from $1,600 2025-03-20
Gpt Academic MEDIUM 6.1
CVE-2024-10812

An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specifie…

No fix yet
Fix from $1,600 2025-03-20
Networker MEDIUM 6.5
CVE-2025-21104

Dell NetWorker, versions prior to 19.11.0.4 and version 19.12, contains an URL Redirection to Untrusted Site ('Open Redirect') Vulnerability in NetWo…

Fix: 19.11.0.4+
Fix from $1,600 2025-03-13
Ad Hoc Infinity HIGH 7.6
CVE-2024-51321

In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled websi…

No fix yet
Fix from $1,950 2025-03-11
Firefox MEDIUM 5.4
CVE-2025-27426

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in …

Fix: 136.0+
Fix from $1,600 2025-03-04
Codechecker MEDIUM 6.1
CVE-2025-1300

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server c…

Fix: 6.24.6+
Fix from $1,600 2025-02-28
Nagios Xi MEDIUM 6.1
CVE-2024-54957

Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability al…

Mitigation only
Fix from $1,600 2025-02-27
Glpi MEDIUM 6.1
CVE-2024-11955

A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of t…

Fix: 10.0.18+
Fix from $1,600 2025-02-25
Better Auth MEDIUM 6.1
CVE-2025-27143

Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is vulnerable to an open redirect…

Fix: 1.1.21+
Fix from $1,600 2025-02-24
Microsoft 365 Graph Mailer MEDIUM 6.1
CVE-2025-1488

The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to…

Fix: after 3.3
Fix from $1,600 2025-02-24
Wpmobile.app MEDIUM 6.1
CVE-2024-13888

The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validat…

Fix: 11.57+
Fix from $1,600 2025-02-20
Mailcow\ HIGH 8.8
CVE-2025-25198

mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset f…

Fix: 2025-01a+
Fix from $1,950 2025-02-12
Dedecms MEDIUM 6.5
CVE-2024-57241

Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in UR…

Mitigation only
Fix from $1,600 2025-02-11
Teamcenter HIGH 7.4
CVE-2025-23363

A vulnerability has been identified in Teamcenter V14.1 (All versions), Teamcenter V14.2 (All versions), Teamcenter V14.3 (All versions < V14.3.0.14)…

Fix: 14.3.0.14 / 2312.0010+
Fix from $1,950 2025-02-11
Unclassified HIGH 7.1
CVE-2025-24868

The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an u…

Mitigation only
Fix from $1,950 2025-02-11
Movidesk MEDIUM 6.1
CVE-2025-0970

A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been declared as problematic. Affected by this vulnerability is an unknown functi…

Fix: after 25.01.22
Fix from $1,600 2025-02-02
Unclassified MEDIUM 6.5
CVE-2024-54728

Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access system logcat logs.

Mitigation only
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.5
CVE-2024-56968

An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted pa…

No fix yet
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.5
CVE-2024-56969

An issue in Pixocial Technology (Singapore) Pte. Ltd BeautyPlus iOS 7.8.010 allows attackers to access sensitive user information via supplying a cra…

No fix yet
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.5
CVE-2024-56971

An issue in Zhiyuan Yuedu (Guangzhou) Literature Information Technology Co., Ltd Shuqi Novel iOS 5.3.8 allows attackers to access sensitive user info…

Mitigation only
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.5
CVE-2024-56972

An issue in Midea Group Co., Ltd Midea Home iOS 9.3.12 allows attackers to access sensitive user information via supplying a crafted link.

No fix yet
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.5
CVE-2024-56955

An issue in Tencent Technology (Shenzhen) Company Limited QQMail iOS 6.6.4 allows attackers to access sensitive user information via supplying a craf…

No fix yet
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.5
CVE-2024-56957

An issue in Kingsoft Office Software Corporation Limited WPS Office iOS 12.20.0 allows attackers to access sensitive user information via supplying a…

No fix yet
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.5
CVE-2024-56959

An issue in Mashang Consumer Finance Co., Ltd Anyihua iOS 3.6.2 allows attackers to access sensitive user information via supplying a crafted link.

No fix yet
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.5
CVE-2024-56960

An issue in Tianjin Xiaowu Information technology Co., Ltd BeiKe Holdings iOS 1.3.50 allows attackers to access sensitive user information via supply…

Mitigation only
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.5
CVE-2024-56962

An issue in Tencent Technology (Shanghai) Co., Ltd WeSing iOS v9.3.39 allows attackers to access sensitive user information via supplying a crafted l…

No fix yet
Fix from $1,600 2025-01-27