Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Connect MEDIUM 6.1
CVE-2024-54051

Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker coul…

Fix: 11.4.9 / 12.7+
Fix from $1,600 2024-12-10
Traefik MEDIUM 6.1
CVE-2024-52003

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-…

Fix: 2.11.14 / 3.2.1+
Fix from $1,600 2024-11-29
Unclassified MEDIUM 5.1
CVE-2024-53264

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in the loading endpoint, allowin…

Mitigation only
Fix from $1,600 2024-11-27
Unclassified MEDIUM 5.9
CVE-2024-8526

A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when visited by an authenticated WebC…

Mitigation only
Fix from $1,600 2024-11-21
User Oidc MEDIUM 6.1
CVE-2024-52512

user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a p…

Fix: 6.1.0+
Fix from $1,600 2024-11-15
Enterprise Chat And Email MEDIUM 6.1
CVE-2022-20634

A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an unde…

Fix: 12.6+
Fix from $1,600 2024-11-15
Pyload MEDIUM 6.1
CVE-2024-1240

An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the…

Patch available
Fix from $1,600 2024-11-15
Central Authentication Service MEDIUM 5.4
CVE-2024-11207

A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the fil…

No fix yet
Fix from $1,600 2024-11-14
Bigfix Compliance MEDIUM 5.4
CVE-2024-30140

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can p…

Mitigation only
Fix from $1,600 2024-11-07
Symfony MEDIUM 6.1
CVE-2024-50345

symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` c…

Fix: 5.4.46 / 6.4.14+
Fix from $1,600 2024-11-06
Bruno MEDIUM 6.5
CVE-2024-48463

Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.

Fix: 1.29.1+
Fix from $1,600 2024-11-04
Access Management MEDIUM 6.1
CVE-2024-25566

An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attac…

Fix: after 7.2.2
Fix from $1,600 2024-10-29
Pbootcms MEDIUM 6.1
CVE-2024-42930

PbootCMS 3.2.8 is vulnerable to URL Redirect.

Mitigation only
Fix from $1,600 2024-10-28
Sunshine Photo Cart MEDIUM 6.1
CVE-2024-50463

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sun…

Fix: 3.2.11+
Fix from $1,600 2024-10-28
Simple Membership MEDIUM 6.1
CVE-2024-49682

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allows Phishing.This issue affect…

Fix: 4.5.4+
Fix from $1,600 2024-10-24
Unclassified MEDIUM 6.1
CVE-2024-46326

Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.

Mitigation only
Fix from $1,600 2024-10-21
Elementsready MEDIUM 6.1
CVE-2024-47353

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in quomodosoft ElementsReady Addons for Elementor element-ready-lite.This issue aff…

Fix: 5.8.1+
Fix from $1,600 2024-10-11
Eventprime MEDIUM 6.1
CVE-2024-47648

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Metagauss EventPrime eventprime-event-calendar-management.This issue affects Eve…

Fix: 4.0.4.6+
Fix from $1,600 2024-10-10
Windows 10 1809 MEDIUM 6.8
CVE-2024-43543

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Fix: 10.0.17763.6414 / 10.0.19044.5011+
Fix from $1,600 2024-10-08
Windows 10 1809 MEDIUM 6.8
CVE-2024-43536

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Fix: 10.0.17763.6414 / 10.0.19044.5011+
Fix from $1,600 2024-10-08
Unclassified MEDIUM 6.1
CVE-2024-45247

Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Mitigation only
Fix from $1,600 2024-10-06
Timeprovider 4100 Firmware MEDIUM 6.1
CVE-2024-43683

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects T…

Fix: 2.4.7+
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-8148

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a …

Mitigation only
Fix from $1,600 2024-10-04
Portal For Arcgis MEDIUM 6.1
CVE-2024-38037

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a …

Mitigation only
Fix from $1,600 2024-10-04
Scout MEDIUM 6.1
CVE-2024-47530

Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users by redirecting them to malicio…

Fix: 4.89+
Fix from $1,600 2024-09-30
Glassfish MEDIUM 6.1
CVE-2024-9329

In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the reque…

Fix: 7.0.17+
Fix from $1,600 2024-09-30
Mostartcms HIGH 7.2
CVE-2024-46331

ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows atta…

No fix yet
Fix from $1,950 2024-09-27
Unclassified HIGH 8.8
CVE-2024-45981

A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via user interaction with a crafte…

Mitigation only
Fix from $1,950 2024-09-26
Unclassified HIGH 8.8
CVE-2024-45979

A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via user interaction with a crafted…

Mitigation only
Fix from $1,950 2024-09-26
Build Of Keycloak MEDIUM 6.1
CVE-2024-8883

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is se…

Mitigation only
Fix from $1,600 2024-09-19