Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Privategpt MEDIUM 6.1
CVE-2024-5936EPSS 29%

An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allo…

No fix yet
Fix from $1,600 2024-06-27
Contact Form 7 MEDIUM 6.1
CVE-2024-4704

The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their…

Fix: 5.9.5+
Fix from $1,600 2024-06-27
Unclassified MEDIUM 6.1
CVE-2024-4604

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields. Th…

Mitigation only
Fix from $1,600 2024-06-26
Seopress MEDIUM 6.1
CVE-2024-4900

The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perf…

Fix: 7.8+
Fix from $1,600 2024-06-24
Gradio MEDIUM 6.1
CVE-2024-4940

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users …

No fix yet
Fix from $1,600 2024-06-22
Export Wp Page To Static Html\/css MEDIUM 6.1
CVE-2024-3597

The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.2.2. This is due to…

Fix: after 2.2.2
Fix from $1,600 2024-06-20
Unclassified MEDIUM 5.3
CVE-2024-37881

SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from …

Mitigation only
Fix from $1,600 2024-06-19
Kibana MEDIUM 6.1
CVE-2024-23442

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted …

Fix: 7.17.22 / 8.14.0+
Fix from $1,600 2024-06-14
Builder MEDIUM 6.1
CVE-2024-3032

Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect iss…

Fix: 7.5.8+
Fix from $1,600 2024-06-13
Strapi HIGH 8.1
CVE-2024-34065

Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query paramet…

Fix: 4.24.2+
Fix from $1,950 2024-06-12
Harbor MEDIUM 6.1
CVE-2024-22244

Open Redirect in Harbor  <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.

Fix: 2.8.5 / 2.9.3+
Fix from $1,600 2024-06-10
Suitecrm MEDIUM 6.1
CVE-2024-36419

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host He…

Fix: 8.6.1+
Fix from $1,600 2024-06-10
Suitecrm MEDIUM 5.4
CVE-2024-36406

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows…

Fix: 7.14.4 / 8.6.1+
Fix from $1,600 2024-06-10
Fortiauthenticator MEDIUM 6.1
CVE-2024-23664

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below …

Fix: 6.5.4+
Fix from $1,600 2024-06-03
Umbraco Cms MEDIUM 6.1
CVE-2024-34071

Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected…

Fix: 8.18.14 / 10.8.6+
Fix from $1,600 2024-05-21
Network Services Orchestrator MEDIUM 6.1
CVE-2024-20369

A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote a…

Fix: 5.5.10.1 / 5.6.14.3+
Fix from $1,600 2024-05-15
Firefox HIGH 7.5
CVE-2024-4773

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfu…

Fix: 126.0+
Fix from $1,950 2024-05-14
Wp Compress MEDIUM 6.1
CVE-2023-6812

The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This…

Fix: 6.20.02+
Fix from $1,600 2024-05-14
Frappe MEDIUM 6.1
CVE-2024-34074

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to u…

Fix: 14.74.0 / 15.26.0+
Fix from $1,600 2024-05-14
Unclassified MEDIUM 6.1
CVE-2024-4133

The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Open Redirect …

Mitigation only
Fix from $1,600 2024-05-02
Unclassified HIGH 8.8
CVE-2024-26504

An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst parameter.

Mitigation only
Fix from $1,950 2024-05-01
Portainer CRITICAL 9.1
CVE-2024-33661

Portainer before 2.20.0 allows redirects when the target is not index.yaml.

Fix: 2.20.0+
Fix from $2,300 2024-04-26
Greenlight MEDIUM 6.1
CVE-2022-36028

Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to …

Fix: 2.13.0+
Fix from $1,600 2024-04-25
Greenlight MEDIUM 6.1
CVE-2022-36029

Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to …

Fix: 2.13.0+
Fix from $1,600 2024-04-25
Unclassified HIGH 7.1
CVE-2024-2419

A flaw was found in Keycloak's redirect_uri validation logic. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attac…

Mitigation only
Fix from $1,950 2024-04-17
Peoplesoft Enterprise Peopletools MEDIUM 6.1
CVE-2024-21065

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are …

Mitigation only
Fix from $1,600 2024-04-16
Unclassified HIGH 8.1
CVE-2024-22262

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the …

Mitigation only
Fix from $1,950 2024-04-16
Gradio MEDIUM 6.5
CVE-2024-1183

An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports wi…

Fix: 4.11.0+
Fix from $1,600 2024-04-16
App Builder MEDIUM 6.1
CVE-2024-31282

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7.

Fix: 3.8.8+
Fix from $1,600 2024-04-10
Wp Oauth Server MEDIUM 6.1
CVE-2024-31253

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4…

Fix: 4.4.0+
Fix from $1,600 2024-04-10