Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Enterprise Manager Base Platform MEDIUM 6.1
CVE-2026-47002

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.1
CVE-2026-8284

URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue aff…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.1
CVE-2026-61901

Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.3
CVE-2026-32824

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Security Verify Access MEDIUM 6.1
CVE-2026-7364

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.2.0
Fix from $1,600 2026-07-17
Unclassified HIGH 8.1
CVE-2026-63094

SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session t…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.8
CVE-2026-12379

An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not prop…

No fix yet
Fix from $1,600 2026-07-16
Redash MEDIUM 6.1
CVE-2026-33213

Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's authentication module stripped…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified CRITICAL 9.6
CVE-2026-61451

The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/…

Mitigation only
Fix from $2,300 2026-07-15
Symfony MEDIUM 6.1
CVE-2026-48784

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGen…

Fix: 5.4.53 / 6.4.41+
Fix from $1,600 2026-07-14
Commerce MEDIUM 6.1
CVE-2026-48000

Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could co…

Fix: 1.21.0+
Fix from $1,600 2026-07-14
Symfony MEDIUM 6.1
CVE-2026-45065

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGen…

Fix: 5.4.52 / 6.4.40+
Fix from $1,600 2026-07-14
Xtraction MEDIUM 6.1
CVE-2026-14902

An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.

Fix: 2026.2.1+
Fix from $1,600 2026-07-14
Unclassified HIGH 8.1
CVE-2026-44745

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthent…

Mitigation only
Fix from $1,950 2026-07-14
Drupal MEDIUM 5.9
CVE-2026-55806

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versi…

Fix: 10.5.12 / 10.6.11+
Fix from $1,600 2026-07-10
Snipe It MEDIUM 6.1
CVE-2026-55461

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer h…

Fix: 8.6.2+
Fix from $1,600 2026-07-10
Cakephp MEDIUM 6.1
CVE-2026-55590

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, …

Fix: 2.11.1 / 3.3.6+
Fix from $1,600 2026-07-09
Cmc HIGH 7.1
CVE-2026-31982

An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirectio…

Fix: 26.2.0+
Fix from $1,950 2026-07-09
Unclassified HIGH 7.4
CVE-2026-59806

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URL…

Patch available
Fix from $1,950 2026-07-08
Coder MEDIUM 6.1
CVE-2026-55431

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder o…

Fix: 2.29.17 / 2.32.7+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.1
CVE-2026-25779

Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.

Patch available
Fix from $1,600 2026-07-03
365 Copilot CRITICAL 9.3
CVE-2026-41106

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified HIGH 7.6
CVE-2026-55660

Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich…

Patch available
Fix from $1,950 2026-07-01
Mediawiki MEDIUM 6.1
CVE-2026-58520

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Fl…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.9
CVE-2026-10562

An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within t…

Mitigation only
Fix from $1,600 2026-06-30
Cacti MEDIUM 6.1
CVE-2026-40080

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring che…

Fix: 1.2.31+
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.4
CVE-2026-52802

Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where attacker-controlled redirect_to …

Patch available
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-13163

Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mailerup <1.0.0 on all platforms…

Patch available
Fix from $1,600 2026-06-24
Unclassified CRITICAL 9.6
CVE-2026-54588

Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` requ…

Mitigation only
Fix from $2,300 2026-06-23
Unclassified MEDIUM 5.1
CVE-2026-47377

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace() o…

Mitigation only
Fix from $1,600 2026-06-23