Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Firefox Mobile MEDIUM 6.1
CVE-2024-0953

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi…

No fix yet
Fix from $1,600 2024-02-05
Rapid Scada MEDIUM 5.4
CVE-2024-21794

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page.

Fix: after 5.8.4
Fix from $1,600 2024-02-02
Wordpress Toolbar MEDIUM 6.1
CVE-2023-6389EPSS 27%

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated atta…

Fix: after 2.2.6
Fix from $1,600 2024-01-29
Keycloak HIGH 7.1
CVE-2023-6291

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful …

Fix: 22.0.7+
Fix from $1,950 2024-01-26
Simple Membership MEDIUM 6.1
CVE-2024-22308

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/…

Fix: 4.4.2+
Fix from $1,600 2024-01-24
Diskstation Manager MEDIUM 5.4
CVE-2024-0854

URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8…

Fix: 7.2.1-69057-2+
Fix from $1,600 2024-01-24
Internet Banking System MEDIUM 6.1
CVE-2024-0781

A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pa…

No fix yet
Fix from $1,600 2024-01-22
Cgi An Anlyzer MEDIUM 6.1
CVE-2024-22113

Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to r…

Fix: after 2023-12-31
Fix from $1,600 2024-01-22
Storage Defender Data Protect MEDIUM 5.4
CVE-2023-50963

IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST he…

Fix: after 1.4.1
Fix from $1,600 2024-01-19
Sso \& Saml Authentication MEDIUM 6.1
CVE-2024-22400

Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server a…

Fix: 5.1.5 / 5.2.5+
Fix from $1,600 2024-01-18
T1 MEDIUM 6.1
CVE-2023-3771

The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

Fix: after 19.0
Fix from $1,600 2024-01-16
Hxtool MEDIUM 6.1
CVE-2024-0319

Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user …

Mitigation only
Fix from $1,600 2024-01-15
Rise Ultimate Project Manager MEDIUM 6.1
CVE-2024-0545

A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the…

Mitigation only
Fix from $1,600 2024-01-15
Zentao MEDIUM 6.1
CVE-2023-49394

Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.

Fix: after 4.1.3
Fix from $1,600 2024-01-10
Marketing MEDIUM 5.4
CVE-2024-21734

SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very …

Mitigation only
Fix from $1,600 2024-01-09
Tasmoadmin MEDIUM 6.1
CVE-2023-6552

Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.

Fix: 3.3.0+
Fix from $1,600 2024-01-08
Dryice Myxalytics MEDIUM 6.1
CVE-2023-50345

HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially l…

Mitigation only
Fix from $1,600 2024-01-03
Follow Redirects MEDIUM 6.1
CVE-2023-26159

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.pa…

Fix: 1.15.4+
Fix from $1,600 2024-01-02
Browser MEDIUM 6.1
CVE-2023-52263

Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_c…

Fix: 1.59.40+
Fix from $1,600 2023-12-30
Calculated Fields Form MEDIUM 5.4
CVE-2023-51517

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: fro…

Fix: after 1.2.28
Fix from $1,600 2023-12-29
Advanced Access Manager MEDIUM 5.4
CVE-2023-51675

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Securi…

Fix: 6.9.19+
Fix from $1,600 2023-12-29
Library Viewer MEDIUM 6.1
CVE-2023-32101

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pexle Chris Library Viewer.This issue affects Library Viewer: from n/a through 2…

Fix: 2.0.6.1+
Fix from $1,600 2023-12-29
Mailchimp MEDIUM 6.1
CVE-2023-32517

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder.T…

Fix: 4.0.9.4+
Fix from $1,600 2023-12-29
Database For Contact Form 7\, Wpforms\, Elementor Forms MEDIUM 6.1
CVE-2023-31095

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja …

Fix: 1.2.9+
Fix from $1,600 2023-12-29
Wp Directory Kit MEDIUM 6.1
CVE-2023-31229

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP Directory Kit.This issue affects WP Directory Kit: from n/a through 1.1.9.

Fix: 1.2.0+
Fix from $1,600 2023-12-29
Zephyr Project Manager MEDIUM 6.1
CVE-2023-31237

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: fr…

Fix: 3.3.91+
Fix from $1,600 2023-12-29
Solid Security MEDIUM 6.1
CVE-2023-28786

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authentication, and Brute Force Pr…

Fix: after 8.1.4
Fix from $1,600 2023-12-29
Asp.net Zero MEDIUM 6.1
CVE-2023-48003

An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any UR…

Fix: 12.3.0+
Fix from $1,600 2023-12-26
Flask Security Too MEDIUM 6.1
CVE-2023-49438

An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites vi…

Fix: after 5.3.2
Fix from $1,600 2023-12-26
Powercms MEDIUM 6.1
CVE-2023-50297

Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary we…

Fix: 4.55 / 5.25+
Fix from $1,600 2023-12-26