Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Fedora MEDIUM 6.5
CVE-2022-36087

OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malic…

Fix: 3.2.1+
Fix from $1,600 2022-09-09
Connect MEDIUM 6.1
CVE-2022-38131

RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious we…

No fix yet
Fix from $1,600 2022-09-06
Security Identity Manager MEDIUM 6.1
CVE-2021-29864

IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a…

Mitigation only
Fix from $1,600 2022-08-30
Oauth2 Server HIGH 7.2
CVE-2020-26938

In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request …

Fix: after 3.1.1
Fix from $1,950 2022-08-29
Hcl Inotes HIGH 7.4
CVE-2022-27547

HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sen…

No fix yet
Fix from $1,950 2022-08-29
Python HIGH 7.4
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI…

Fix: 3.7.14 / 3.8.14+
Fix from $1,950 2022-08-23
Mod Auth Mellon MEDIUM 6.1
CVE-2021-3639

A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing a…

Fix: 0.18.0+
Fix from $1,600 2022-08-22
Vince MEDIUM 6.1
CVE-2022-25799

An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has a specially crafted URL and c…

Fix: 1.50.0+
Fix from $1,600 2022-08-16
Bookwyrm MEDIUM 6.1
CVE-2022-35953

BookWyrm is a social network for tracking your reading, talking about books, writing reviews, and discovering what to read next. Some links in BookWy…

Fix: 0.4.5+
Fix from $1,600 2022-08-12
Virtual Desktop Infrastructure MEDIUM 6.1
CVE-2022-28755

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a…

Fix: 5.10.7 / 5.11.0+
Fix from $1,600 2022-08-11
Identity Manager CRITICAL 9.8
CVE-2022-31657

VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect…

Patch available
Fix from $2,300 2022-08-05
Flask Security MEDIUM 6.1
CVE-2021-23385

This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to…

No fix yet
Fix from $1,600 2022-08-02
Dspace MEDIUM 6.1
CVE-2022-31193

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace…

Fix: 6.4+
Fix from $1,600 2022-08-01
Gateway MEDIUM 6.1
CVE-2022-27509

Unauthenticated redirection to a malicious website

Fix: 12.1-55.282 / 12.1-65.15+
Fix from $1,600 2022-07-28
Booked MEDIUM 6.1
CVE-2022-30706

Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and …

Fix: 3.3.0+
Fix from $1,600 2022-07-26
Moodle MEDIUM 6.1
CVE-2022-35652

An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can cre…

Fix: 3.9.15 / 3.11.8+
Fix from $1,600 2022-07-25
Undici MEDIUM 6.5
CVE-2022-31151

Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the…

Fix: 5.7.1+
Fix from $1,600 2022-07-21
Request Tracker MEDIUM 6.1
CVE-2022-25803

Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.

Fix: 5.0.3+
Fix from $1,600 2022-07-14
Camera MEDIUM 5.3
CVE-2022-33712

Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S…

Fix: 12.0.0.98 / 12.0.01.64+
Fix from $1,600 2022-07-12
GitLab MEDIUM 6.1
CVE-2022-2250

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, all…

Fix: 14.0.5 / 14.10.5+
Fix from $1,600 2022-07-01
Server MEDIUM 6.1
CVE-2017-20119

A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lan…

Fix: 5.0.2+
Fix from $1,600 2022-06-29
Microweber MEDIUM 6.1
CVE-2022-2252

Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

Fix: 1.2.19+
Fix from $1,600 2022-06-29
Oauth 2.0 Server MEDIUM 6.1
CVE-2020-26877

ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specif…

Mitigation only
Fix from $1,600 2022-06-29
Nagios Xi MEDIUM 6.1
CVE-2022-29272

In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.

Fix: after 5.8.5
Fix from $1,600 2022-06-29
Web2py MEDIUM 6.1
CVE-2022-33146

Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phi…

Fix: 2.22.5+
Fix from $1,600 2022-06-27
Habitica MEDIUM 5.8
CVE-2022-23078

In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.

Fix: 4.233.0+
Fix from $1,600 2022-06-22
U5cms MEDIUM 6.1
CVE-2022-32444

An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another si…

No fix yet
Fix from $1,600 2022-06-17
Open Forms MEDIUM 6.1
CVE-2022-31040

Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie consent page in Open Forms contai…

Fix: 1.0.9+
Fix from $1,600 2022-06-13
Dubbo MEDIUM 6.1
CVE-2022-24969

bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic…

Fix: 2.6.12 / 2.7.15+
Fix from $1,600 2022-06-09
Caddy MEDIUM 6.1
CVE-2022-29718

Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect use…

Fix: 2.5.0+
Fix from $1,600 2022-06-02