Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
E Series Santricity Os Controller MEDIUM 6.1
CVE-2022-23237

E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker…

Fix: after 11.70.2
Fix from $1,600 2022-06-02
Next Auth MEDIUM 6.1
CVE-2022-29214

NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vuln…

Fix: 3.29.3 / 4.3.3+
Fix from $1,600 2022-05-21
Grafana HIGH 8.5
CVE-2022-29170

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to config…

Fix: 7.5.16 / 8.5.3+
Fix from $1,950 2022-05-20
Drawio MEDIUM 6.1
CVE-2022-1774

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.

Fix: 18.0.7+
Fix from $1,600 2022-05-18
Cyber Protect MEDIUM 6.1
CVE-2022-30992

Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

Fix: 15+
Fix from $1,600 2022-05-18
Sma 6200 Firmware MEDIUM 6.1
CVE-2022-1702EPSS 9%

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site …

Mitigation only
Fix from $1,600 2022-05-13
Sysaid MEDIUM 6.1
CVE-2022-22797

Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" request from the url location: /Com…

Fix: 22.1.50 / 22.1.64+
Fix from $1,600 2022-05-12
Ultimate Member MEDIUM 5.4
CVE-2022-1209

The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of…

Fix: after 2.3.1
Fix from $1,600 2022-05-10
Qts MEDIUM 6.1
CVE-2021-44054

An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows …

Fix: 4.3.3.1945 / 4.3.4.1976+
Fix from $1,600 2022-05-05
Telepresence Collaboration Endpoint HIGH 8.1
CVE-2022-20764

Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote …

Fix: 10.8.2.5 / 2021-05+
Fix from $1,950 2022-05-04
Nopcommerce MEDIUM 6.1
CVE-2022-27461

In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafte…

Fix: after 4.50.1
Fix from $1,600 2022-05-04
Netiq Access Manager MEDIUM 6.1
CVE-2022-26326

Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2

Fix: 5.0.2+
Fix from $1,600 2022-05-02
Talk MEDIUM 6.1
CVE-2022-24887

Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0…

Fix: 11.3.4 / 12.2.4+
Fix from $1,600 2022-04-27
English Wordpress Admin MEDIUM 6.1
CVE-2021-25111

The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leadi…

Fix: 1.5.2+
Fix from $1,600 2022-04-25
Mi App Store MEDIUM 6.1
CVE-2020-14118

An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the…

Fix: 4.10.0+
Fix from $1,600 2022-04-21
Web Gateway MEDIUM 6.1
CVE-2022-1254

A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.…

Fix: 7.8.2.31 / 8.2.27+
Fix from $1,600 2022-04-20
Next Auth MEDIUM 6.1
CVE-2022-24858

next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2…

Fix: 3.29.2 / 4.3.2+
Fix from $1,600 2022-04-19
Webctrl Server MEDIUM 6.1
CVE-2022-1019

Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a ma…

Fix: after 7.0
Fix from $1,600 2022-04-19
Posthog MEDIUM 6.1
CVE-2022-0645

Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.

Fix: 1.34.1+
Fix from $1,600 2022-04-19
Datamodule Compactplus MEDIUM 6.1
CVE-2020-25154

An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data…

Mitigation only
Fix from $1,600 2022-04-14
Hubzilla MEDIUM 6.1
CVE-2022-27256

A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files…

Fix: 7.2+
Fix from $1,600 2022-04-13
Orangehrm MEDIUM 5.4
CVE-2022-27109

OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.

No fix yet
Fix from $1,600 2022-04-06
Orangehrm MEDIUM 5.4
CVE-2022-27110

OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.

No fix yet
Fix from $1,600 2022-04-06
Avideo MEDIUM 6.1
CVE-2022-27463

Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url …

Fix: after 11.6
Fix from $1,600 2022-04-05
Uri.js MEDIUM 6.1
CVE-2022-1233

URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.

Fix: 1.19.11+
Fix from $1,600 2022-04-04
Express Openid Connect MEDIUM 6.1
CVE-2022-24794

Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middle…

Fix: 2.7.2+
Fix from $1,600 2022-03-31
Joomla\! MEDIUM 6.1
CVE-2022-23798

An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check wheth…

Fix: after 4.1.0
Fix from $1,600 2022-03-30
Archer MEDIUM 6.1
CVE-2022-26950

Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate…

Fix: 6.9.0.3+
Fix from $1,600 2022-03-30
Symantec Siteminder MEDIUM 6.1
CVE-2005-10001

A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/s…

Mitigation only
Fix from $1,600 2022-03-28
GitLab MEDIUM 6.1
CVE-2022-0283

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a…

Fix: 14.5.4 / 14.6.4+
Fix from $1,600 2022-03-28