Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Instantcms MEDIUM 5.4
CVE-2024-31213

InstantCMS is a free and open source content management system. An open redirect was found in the ICMS2 application version 2.16.2 when being redirec…

Fix: 2.16.2+
Fix from $1,600 2024-04-05
Unclassified HIGH 7.3
CVE-2024-28287

A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a c…

Mitigation only
Fix from $1,950 2024-04-02
Unclassified HIGH 7.1
CVE-2024-22248

VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker controlled do…

Mitigation only
Fix from $1,950 2024-04-02
Teamcity MEDIUM 6.1
CVE-2024-31135

In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

Fix: 2024.03+
Fix from $1,600 2024-03-28
Uncanny Toolkit For Learndash MEDIUM 6.1
CVE-2023-34020

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for…

Fix: after 3.6.4.3
Fix from $1,600 2024-03-27
Express MEDIUM 6.1
CVE-2024-29041

Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected …

Fix: 4.19.2+
Fix from $1,600 2024-03-25
Cdex HIGH 7.1
CVE-2024-2465

Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafted URL.This issue affects CDeX…

Fix: after 5.71
Fix from $1,950 2024-03-21
Docassemble MEDIUM 6.1
CVE-2024-27291

Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a URL that acts as an open red…

Fix: 1.4.97+
Fix from $1,600 2024-03-21
Espocrm MEDIUM 5.9
CVE-2024-24818

EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redi…

Fix: 8.1.2+
Fix from $1,600 2024-03-21
Travelpayouts MEDIUM 6.1
CVE-2024-0337

The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on th…

Fix: 1.1.17+
Fix from $1,600 2024-03-20
Unclassified MEDIUM 5.4
CVE-2024-25657

An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could allow atta…

Mitigation only
Fix from $1,600 2024-03-18
Spring Framework HIGH 8.1
CVE-2024-22259

Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform valid…

Fix: 5.3.33 / 6.0.18+
Fix from $1,950 2024-03-16
Peering Manager MEDIUM 6.1
CVE-2024-28113

Peering Manager is a BGP session management tool. In Peering Manager <=1.8.2, it is possible to redirect users to an arbitrary page using a crafted u…

Fix: 1.8.3+
Fix from $1,600 2024-03-12
Unclassified MEDIUM 6.5
CVE-2024-1227

An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a legitimate page to a maliciou…

Mitigation only
Fix from $1,600 2024-03-12
Nteract CRITICAL 9.8
CVE-2024-22891

Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.

No fix yet
Fix from $2,300 2024-03-01
Unclassified HIGH 8.1
CVE-2024-22243

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the …

Mitigation only
Fix from $1,950 2024-02-23
Vdesk MEDIUM 5.4
CVE-2022-45169

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/…

Fix: after 031
Fix from $1,600 2024-02-21
Jumpserver MEDIUM 6.1
CVE-2024-24763

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this…

Fix: 3.10.0+
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 6.1
CVE-2024-25608

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before up…

Fix: 7.2 / 7.4.3.19+
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 6.1
CVE-2024-25609

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pa…

Fix: 7.2 / 7.4.3.13+
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 6.1
CVE-2023-44308

Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote a…

Mitigation only
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 6.1
CVE-2023-5190

Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 befo…

Fix: 7.4.3.102+
Fix from $1,600 2024-02-20
Caddy Security MEDIUM 6.1
CVE-2024-21497

Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform…

Mitigation only
Fix from $1,600 2024-02-17
Threat Visualizer MEDIUM 6.1
CVE-2024-22854

DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been iden…

Fix: after 6.1.27
Fix from $1,600 2024-02-16
Osticky MEDIUM 6.1
CVE-2024-21728

An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joom…

Fix: 2.2.8+
Fix from $1,600 2024-02-15
Analytics Insights MEDIUM 6.1
CVE-2024-0250

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the…

Fix: 6.3+
Fix from $1,600 2024-02-12
Glewlwyd Sso Server MEDIUM 6.1
CVE-2024-25715

Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.

Fix: after 2.7.6
Fix from $1,600 2024-02-11
S.i.l MEDIUM 6.1
CVE-2024-24034

Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.

No fix yet
Fix from $1,600 2024-02-08
Yzmcms MEDIUM 6.1
CVE-2024-24291

An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.

No fix yet
Fix from $1,600 2024-02-06
Pyload MEDIUM 6.1
CVE-2024-24808

pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values…

Fix: after 0.5.0
Fix from $1,600 2024-02-06