Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Wooframework Branding MEDIUM 6.1
CVE-2015-10112

A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_scr…

Fix: after 1.0.1
Fix from $1,600 2023-06-05
Firefox MEDIUM 6.1
CVE-2023-29540

Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <cod…

Fix: 112.0+
Fix from $1,600 2023-06-02
Firefox HIGH 8.1
CVE-2023-25734

After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpecte…

Fix: 102.8 / 110.0+
Fix from $1,950 2023-06-02
Ix Workforce Engagement MEDIUM 6.1
CVE-2023-32218

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Mitigation only
Fix from $1,600 2023-05-30
Joomla\! MEDIUM 6.1
CVE-2023-23754

An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection s…

Fix: 4.3.2+
Fix from $1,600 2023-05-30
Identity Manager MEDIUM 6.1
CVE-2023-20884

VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to…

Fix: after 22.09.1.0
Fix from $1,600 2023-05-30
Tornado MEDIUM 6.1
CVE-2023-28370

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web sit…

Fix: 6.3.2+
Fix from $1,600 2023-05-25
Orvc MEDIUM 6.1
CVE-2023-31245

Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impers…

Fix: 7.3.0+
Fix from $1,600 2023-05-22
Xwiki MEDIUM 6.1
CVE-2023-32068EPSS 55%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible t…

Fix: 14.10.4+
Fix from $1,600 2023-05-15
Portal For Arcgis MEDIUM 6.1
CVE-2023-25829

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a …

No fix yet
Fix from $1,600 2023-05-09
Tauri MEDIUM 5.4
CVE-2023-31134

Tauri is software for building applications for multi-platform deployment. The Tauri IPC is usually strictly isolated from external websites, but in …

Fix: 1.0.9 / 1.1.4+
Fix from $1,600 2023-05-09
Typecho MEDIUM 6.1
CVE-2020-21038

Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.

No fix yet
Fix from $1,600 2023-05-08
GitLab MEDIUM 5.4
CVE-2023-0155

An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitr…

Fix: 15.8.5 / 15.9.5+
Fix from $1,600 2023-05-03
Mattermost Desktop MEDIUM 5.4
CVE-2023-2000

Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website

Fix: after 5.2.2
Fix from $1,600 2023-05-02
Icons For Features MEDIUM 6.1
CVE-2015-10104

A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some …

Patch available
Fix from $1,600 2023-04-30
Framework MEDIUM 6.1
CVE-2023-22729

Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an at…

Fix: 4.12.5+
Fix from $1,600 2023-04-26
Lorawan Stack MEDIUM 6.1
CVE-2023-26494

lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login page of the lorawan stack serve…

Fix: 3.24.1+
Fix from $1,600 2023-04-24
Freshdesk MEDIUM 6.1
CVE-2015-10102

A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this issue is some unknown functi…

Patch available
Fix from $1,600 2023-04-17
Xwiki MEDIUM 6.1
CVE-2023-29204

XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put i…

Fix: 13.10.10 / 14.4.4+
Fix from $1,600 2023-04-15
Servicenow MEDIUM 6.1
CVE-2022-46886

There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domai…

Mitigation only
Fix from $1,600 2023-04-14
Edge Chromium MEDIUM 6.1
CVE-2023-24935

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Fix: 112.0.5615.49+
Fix from $1,600 2023-04-11
Fortiproxy MEDIUM 5.4
CVE-2023-22641

A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS v…

Fix: 6.4.13 / 7.0.9+
Fix from $1,600 2023-04-11
Streaming Data Platform MEDIUM 5.4
CVE-2023-28069

Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to re…

Fix: 1.4+
Fix from $1,600 2023-04-05
Emui HIGH 7.4
CVE-2022-48358

The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerability by a malicious app can cause service excepti…

No fix yet
Fix from $1,950 2023-03-27
Keycloak Node.js Adapter MEDIUM 6.1
CVE-2022-2237

A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso functio…

Mitigation only
Fix from $1,600 2023-03-27
Uri MEDIUM 6.1
CVE-2023-28628

lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an attacker to send malicious UR…

Fix: 1.14.120+
Fix from $1,600 2023-03-27
Twofactorauth MEDIUM 6.1
CVE-2016-15030

A vulnerability classified as problematic has been found in Arno0x TwoFactorAuth. This affects an unknown part of the file login/login.php. The manip…

Fix: 2016-01-27+
Fix from $1,600 2023-03-25
Experience Manager MEDIUM 5.4
CVE-2023-22259

Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privile…

Fix: 6.5.16.0 / 2023.1.0+
Fix from $1,600 2023-03-22
Experience Manager MEDIUM 5.4
CVE-2023-22260

Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privile…

Fix: 6.5.16.0 / 2023.1.0+
Fix from $1,600 2023-03-22
Experience Manager MEDIUM 5.4
CVE-2023-22261

Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privile…

Fix: 6.5.16.0 / 2023.1.0+
Fix from $1,600 2023-03-22