Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Seraphinite Accelerator MEDIUM 5.4
CVE-2023-5610

The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary r…

Fix: 2.2.29+
Fix from $1,600 2023-11-20
Epolicy Orchestrator MEDIUM 5.4
CVE-2023-5445

An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter …

Fix: 5.10.0+
Fix from $1,600 2023-11-17
Payara MEDIUM 6.1
CVE-2023-41699

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation module…

Fix: 4.1.2.191.46 / 5.57.0+
Fix from $1,600 2023-11-15
Ecostruxure Power Monitoring Expert MEDIUM 6.1
CVE-2023-5986

A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting att…

Mitigation only
Fix from $1,600 2023-11-15
Dompurify MEDIUM 6.1
CVE-2019-25155

DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.

Fix: 1.0.11+
Fix from $1,600 2023-11-07
Online Examination System MEDIUM 6.1
CVE-2023-45203

Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacke…

No fix yet
Fix from $1,600 2023-11-01
Online Examination System MEDIUM 6.1
CVE-2023-45202

Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker…

No fix yet
Fix from $1,600 2023-11-01
Online Examination System MEDIUM 6.1
CVE-2023-45201

Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacke…

No fix yet
Fix from $1,600 2023-11-01
Adaptive Security Appliance Software MEDIUM 6.1
CVE-2023-20264

A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive S…

Fix: after 9.19.1.12
Fix from $1,600 2023-11-01
Workspace One Uem MEDIUM 6.1
CVE-2023-20886

VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and ret…

Fix: 22.3.0.48 / 22.6.0.36+
Fix from $1,600 2023-10-31
Asset Management X MEDIUM 6.1
CVE-2023-4964

Potential open redirect vulnerability in opentext Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.…

Mitigation only
Fix from $1,600 2023-10-30
Sisqualwfm MEDIUM 6.1
CVE-2023-36085

The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By…

Fix: 7.1.319.111+
Fix from $1,600 2023-10-25
Django Grappelli MEDIUM 6.1
CVE-2021-46898

views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does …

Fix: 2.15.2+
Fix from $1,600 2023-10-22
Zzzphp MEDIUM 6.1
CVE-2023-45909

zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.

Patch available
Fix from $1,600 2023-10-18
Urllib3 MEDIUM 6.1
CVE-2018-25091

urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, po…

Fix: 1.24.2+
Fix from $1,600 2023-10-15
Mosparo MEDIUM 6.1
CVE-2023-5375EPSS 35%

Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.

Fix: 1.0.2+
Fix from $1,600 2023-10-04
GitLab HIGH 7.1
CVE-2023-3922

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all ve…

Fix: 16.2.8 / 16.3.5+
Fix from $1,950 2023-09-29
Identity Portal MEDIUM 5.4
CVE-2023-23957

An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4

No fix yet
Fix from $1,600 2023-09-19
Deep Castle G2 MEDIUM 6.1
CVE-2023-40779

An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

Mitigation only
Fix from $1,600 2023-09-14
Couchcms MEDIUM 6.1
CVE-2023-41609

An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site v…

No fix yet
Fix from $1,600 2023-09-11
S\/4hana MEDIUM 6.1
CVE-2023-40306

SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient UR…

Mitigation only
Fix from $1,600 2023-09-08
Hyperflex Hx Data Platform MEDIUM 6.1
CVE-2023-20263

A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect…

Mitigation only
Fix from $1,600 2023-09-06
Fedora MEDIUM 5.4
CVE-2023-39364

Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console access can be redirected to an arb…

No fix yet
Fix from $1,600 2023-09-05
Video Insight MEDIUM 6.1
CVE-2023-38574

Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and con…

Fix: 7.9.6+
Fix from $1,600 2023-09-05
Softswitch MEDIUM 6.1
CVE-2023-39371

StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601)

Mitigation only
Fix from $1,600 2023-09-03
GitLab MEDIUM 6.1
CVE-2023-1279

An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all ver…

Fix: 16.1.5 / 16.2.5+
Fix from $1,600 2023-09-01
Jupyter Server MEDIUM 6.1
CVE-2023-39968

jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can…

Fix: 2.7.2+
Fix from $1,600 2023-08-28
Tomcat MEDIUM 6.1
CVE-2023-41080EPSS 6%

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from…

Fix: after 10.1.12
Fix from $1,600 2023-08-25
Horizon MEDIUM 6.1
CVE-2022-45582

Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.

Fix: after 20.1.4
Fix from $1,600 2023-08-22
Titan Ftp Server MEDIUM 6.1
CVE-2022-44215

There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.

Fix: after 19.0
Fix from $1,600 2023-08-22