Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Firefox MEDIUM 6.1
CVE-2024-8897EPSS 7%

Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to s…

Fix: 130.0.1+
Fix from $1,600 2024-09-17
Share This Image MEDIUM 6.1
CVE-2024-8761

The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient vali…

Fix: 2.04+
Fix from $1,600 2024-09-17
GitLab MEDIUM 6.1
CVE-2024-4283

An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under …

Fix: 17.1.7 / 17.2.5+
Fix from $1,600 2024-09-16
GitLab MEDIUM 6.1
CVE-2024-4612

An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under …

Fix: 17.1.7 / 17.2.5+
Fix from $1,600 2024-09-12
Payara MEDIUM 6.1
CVE-2024-7312

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session…

Fix: 4.1.2.191.50 / 5.67.0+
Fix from $1,600 2024-09-11
Glassfish MEDIUM 6.1
CVE-2024-8646

In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulner…

Fix: 7.0.10+
Fix from $1,600 2024-09-11
Build Of Keycloak MEDIUM 6.1
CVE-2024-7260

An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are m…

Fix: 24.0.7+
Fix from $1,600 2024-09-09
Webitr MEDIUM 6.1
CVE-2024-8586

WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users,…

Fix: 2_1_0_28+
Fix from $1,600 2024-09-09
Queuemetrics MEDIUM 6.1
CVE-2024-42341

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Fix: 24.05.5+
Fix from $1,600 2024-09-08
Clinic\'s Patient Management System MEDIUM 6.1
CVE-2024-8555

A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown func…

No fix yet
Fix from $1,600 2024-09-07
Shakal Ng MEDIUM 6.1
CVE-2024-8412

A vulnerability, which was classified as problematic, was found in LinuxOSsk Shakal-NG up to 1.3.3. Affected is an unknown function of the file comme…

Fix: after 1.3.3
Fix from $1,600 2024-09-04
Firefox MEDIUM 6.1
CVE-2024-8386

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofin…

Fix: 128.2 / 130.0+
Fix from $1,600 2024-09-03
Vtiger Crm MEDIUM 6.1
CVE-2024-44776

An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.

No fix yet
Fix from $1,600 2024-08-29
Security Verify Access HIGH 8.2
CVE-2024-35133

IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open…

Fix: after 10.0.8
Fix from $1,950 2024-08-29
Gnuboard MEDIUM 6.1
CVE-2024-39097

There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.

Fix: 6.0.5+
Fix from $1,600 2024-08-26
Unclassified MEDIUM 6.1
CVE-2024-43794

OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper vali…

Patch available
Fix from $1,600 2024-08-23
Joomla\! MEDIUM 6.1
CVE-2024-27184

Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

Fix: 3.10.17 / 4.4.7+
Fix from $1,600 2024-08-20
3dexperience MEDIUM 6.1
CVE-2024-6377

An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release …

Mitigation only
Fix from $1,600 2024-08-20
Salon Booking System MEDIUM 6.1
CVE-2024-43280

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking syste…

Fix: 10.9+
Fix from $1,600 2024-08-19
Open Journal Systems MEDIUM 6.1
CVE-2024-7902

A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /l…

Fix: after 3.4.0-6
Fix from $1,600 2024-08-17
Webob MEDIUM 6.1
CVE-2024-42353

WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by…

Fix: 1.8.8+
Fix from $1,600 2024-08-14
Dynamics 365 HIGH 8.2
CVE-2024-38211

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Patch available
Fix from $1,950 2024-08-13
Platform MEDIUM 6.1
CVE-2024-7211

The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attack…

Mitigation only
Fix from $1,600 2024-08-01
Mobile Security Framework MEDIUM 5.4
CVE-2024-41955

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulner…

Fix: 4.0.5+
Fix from $1,600 2024-07-31
Openproject MEDIUM 6.1
CVE-2024-41801

OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the default configuration of packaged …

Fix: 14.3.0+
Fix from $1,600 2024-07-25
Wps Hide Login MEDIUM 6.1
CVE-2024-6289

The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing a…

Fix: 1.9.16.4+
Fix from $1,600 2024-07-15
Workspace MEDIUM 6.1
CVE-2024-6149

Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5

Fix: 2404.1+
Fix from $1,600 2024-07-10
Netscaler Application Delivery Controller MEDIUM 6.1
CVE-2024-5492

Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway

Fix: 12.1-55.304 / 13.0-92.31+
Fix from $1,600 2024-07-10
Outline MEDIUM 6.1
CVE-2024-37830

An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.

Fix: after 0.76.1
Fix from $1,600 2024-07-09
Unclassified MEDIUM 5.3
CVE-2024-4882

The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.

Mitigation only
Fix from $1,600 2024-07-08