Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Caddy MEDIUM 6.1
CVE-2022-28923

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted UR…

Patch available
Fix from $1,600 2023-02-06
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2023-22418

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirec…

Fix: 14.1.5.3 / 15.1.7+
Fix from $1,600 2023-02-01
Openid MEDIUM 6.1
CVE-2023-24445

Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins.

Fix: after 2.4
Fix from $1,600 2023-01-26
Obsidian MEDIUM 6.1
CVE-2023-24044

A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host…

Fix: after 18.0.49
Fix from $1,600 2023-01-22
Pgadmin 4 MEDIUM 6.1
CVE-2023-22298

Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site…

Fix: 6.14+
Fix from $1,600 2023-01-17
Superset MEDIUM 5.4
CVE-2022-43721

An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site wh…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Gibb Modul 151 MEDIUM 6.1
CVE-2015-10052

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in calesanz gibb-modul-151. This affects the function…

Fix: 2015-03-19+
Fix from $1,600 2023-01-15
Saml Authentication MEDIUM 6.1
CVE-2022-39183

Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.

Mitigation only
Fix from $1,600 2023-01-12
GitLab MEDIUM 6.1
CVE-2023-0042

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.…

Fix: 15.5.7 / 15.6.4+
Fix from $1,600 2023-01-12
Secure Login MEDIUM 6.1
CVE-2023-22958

The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidati…

Fix: 3.1.1.0+
Fix from $1,600 2023-01-11
Seed MEDIUM 6.1
CVE-2017-20164

A vulnerability was found in Symbiote Seed up to 6.0.2. It has been classified as critical. Affected is the function onBeforeSecurityLogin of the fil…

Fix: 6.0.3+
Fix from $1,600 2023-01-07
Octopus Server MEDIUM 6.1
CVE-2022-3614

In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and …

Fix: 2022.3.10750 / 2022.4.8063+
Fix from $1,600 2023-01-03
Portal For Arcgis MEDIUM 6.1
CVE-2022-38208

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a UR…

Fix: after 11.0
Fix from $1,600 2022-12-29
Rdiffweb MEDIUM 6.1
CVE-2022-4720

Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.

Fix: 2.5.5+
Fix from $1,600 2022-12-27
I18n MEDIUM 6.1
CVE-2020-36627

A vulnerability was found in Macaron i18n. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the fil…

Fix: 0.5.0+
Fix from $1,600 2022-12-25
Firefox MEDIUM 6.1
CVE-2022-45413

Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be…

Fix: 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-36316

When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL ha…

Fix: 103.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-34474

Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol…

Fix: 102.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-34478

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser,…

Fix: 91.11 / 102.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-29912

Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefo…

Fix: 91.9 / 100.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-29910

When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Fi…

Fix: 100.0+
Fix from $1,600 2022-12-22
Rdiffweb MEDIUM 6.1
CVE-2022-4644

Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.

Fix: 2.5.4+
Fix from $1,600 2022-12-22
Experience Manager MEDIUM 5.4
CVE-2022-44488

Adobe Experience Manager version 6.5.14 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privi…

Fix: 6.5.15.0 / 2022.10.0+
Fix from $1,600 2022-12-19
Oils Js MEDIUM 6.1
CVE-2021-4260

A vulnerability was found in oils-js. It has been declared as critical. This vulnerability affects unknown code of the file core/Web.js. The manipula…

Fix: 2021-03-23+
Fix from $1,600 2022-12-19
Helix MEDIUM 6.1
CVE-2022-47500

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache H…

Fix: after 1.0.4
Fix from $1,600 2022-12-19
Hcl Digital Experience MEDIUM 6.1
CVE-2022-38662

 In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.

Mitigation only
Fix from $1,600 2022-12-19
Electronic Bidding Core System MEDIUM 6.1
CVE-2022-46288

Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitr…

Fix: after 6
Fix from $1,600 2022-12-19
Django Terms And Conditions MEDIUM 6.1
CVE-2022-4589

A vulnerability has been found in cyface Terms and Conditions Module up to 2.0.9 and classified as problematic. Affected by this vulnerability is the…

Fix: 2.0.10+
Fix from $1,600 2022-12-17
Debian Linux MEDIUM 6.1
CVE-2022-23527

mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulne…

Fix: 2.4.12.2+
Fix from $1,600 2022-12-14
Contract Lifecycle Manager MEDIUM 6.1
CVE-2022-41273

Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicio…

Mitigation only
Fix from $1,600 2022-12-13