Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Solution Manager MEDIUM 6.1
CVE-2022-41275

In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in …

Mitigation only
Fix from $1,600 2022-12-13
Oneview Global Dashboard MEDIUM 6.1
CVE-2022-37927

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD).

Fix: 2.7+
Fix from $1,600 2022-12-12
Google Login MEDIUM 6.1
CVE-2022-46683

Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkin…

Fix: 1.7+
Fix from $1,600 2022-12-12
Ilias MEDIUM 6.1
CVE-2022-45917

ILIAS before 7.16 has an Open Redirect.

Fix: 7.16+
Fix from $1,600 2022-12-07
Nimbus CRITICAL 9.3
CVE-2022-41559

The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows an unauthenticated attacker w…

Mitigation only
Fix from $2,300 2022-12-06
Shirasagi MEDIUM 6.1
CVE-2022-43479

Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and c…

Fix: after 1.15.0
Fix from $1,600 2022-12-05
Opencast MEDIUM 6.1
CVE-2022-41965

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 12.5, Opencast's Paella …

Fix: 12.5+
Fix from $1,600 2022-11-28
Kibana MEDIUM 6.1
CVE-2021-22141

An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in…

Fix: 6.8.16 / 7.13.0+
Fix from $1,600 2022-11-18
Arcgis Quickcapture MEDIUM 6.1
CVE-2022-38201

An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticate…

Fix: after 10.9.1
Fix from $1,600 2022-11-15
Airflow MEDIUM 6.1
CVE-2022-45402EPSS 82%

In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.

Fix: 2.4.3+
Fix from $1,600 2022-11-15
GitLab MEDIUM 6.1
CVE-2022-3486

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allow…

Fix: 15.3.5 / 15.4.4+
Fix from $1,600 2022-11-09
GitLab MEDIUM 6.1
CVE-2022-3280

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker …

Fix: 15.3.5 / 15.4.4+
Fix from $1,600 2022-11-09
Emui MEDIUM 5.3
CVE-2022-44560

The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modif…

Mitigation only
Fix from $1,600 2022-11-09
Biller Direct MEDIUM 6.1
CVE-2022-41207

SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsens…

No fix yet
Fix from $1,600 2022-11-08
Airflow MEDIUM 6.1
CVE-2022-43985

In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.

Fix: 2.4.2+
Fix from $1,600 2022-11-02
Apinto Dashboard MEDIUM 6.1
CVE-2022-3797

A vulnerability was found in eolinker apinto-dashboard. It has been rated as problematic. This issue affects some unknown processing of the file /log…

No fix yet
Fix from $1,600 2022-11-01
Meetings CRITICAL 9.6
CVE-2022-28763

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a …

Fix: 5.12.2+
Fix from $2,300 2022-10-31
U Office Force MEDIUM 6.1
CVE-2022-39021

U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vulnerability to redirect user …

Fix: after 20.50.7821d
Fix from $1,600 2022-10-31
Metabase MEDIUM 6.5
CVE-2022-39359

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL…

Fix: 0.41.9 / 0.42.6+
Fix from $1,600 2022-10-26
Arcgis Server MEDIUM 6.1
CVE-2022-38197

Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user int…

Fix: after 10.9.1
Fix from $1,600 2022-10-25
Nopcommerce MEDIUM 6.1
CVE-2022-26954

Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to …

Fix: 4.50.2+
Fix from $1,600 2022-10-20
Commerce HIGH 8.8
CVE-2022-41204

An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject …

Mitigation only
Fix from $1,950 2022-10-11
Rdiffweb MEDIUM 6.1
CVE-2022-3438

Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

Fix: 2.5.0+
Fix from $1,600 2022-10-10
Echo CRITICAL 9.6
CVE-2022-40083

Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged b…

Patch available
Fix from $2,300 2022-09-28
Mailcow\ HIGH 8.2
CVE-2022-39258

mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Author…

Fix: 2022-09+
Fix from $1,950 2022-09-27
Digital Experience Platform MEDIUM 6.1
CVE-2022-28977

HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack …

Fix: 7.4.3.4+
Fix from $1,600 2022-09-22
Airflow MEDIUM 6.1
CVE-2022-40754

In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.

Fix: after 2.3.4
Fix from $1,600 2022-09-21
Openam MEDIUM 6.1
CVE-2022-31735

OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected …

Fix: after 14.2.0-2
Fix from $1,600 2022-09-15
1350 Optical Management System MEDIUM 6.1
CVE-2022-39814

In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.

Mitigation only
Fix from $1,600 2022-09-13
Gophish MEDIUM 5.4
CVE-2022-25295

This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The applicatio…

Fix: 0.12.0+
Fix from $1,600 2022-09-11