Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Flask Appbuilder MEDIUM 6.1
CVE-2022-24776

Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnera…

Fix: 3.4.5+
Fix from $1,600 2022-03-24
Gitea MEDIUM 6.1
CVE-2022-1058EPSS 53%

Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.

Fix: 1.16.5+
Fix from $1,600 2022-03-24
Cscms MEDIUM 5.4
CVE-2022-27090

Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.

No fix yet
Fix from $1,600 2022-03-21
Kingcomposer MEDIUM 6.1
CVE-2022-0165

The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thum…

Fix: after 2.9.6
Fix from $1,600 2022-03-14
Moodle MEDIUM 6.1
CVE-2021-32478

The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 t…

Fix: 3.8.9 / 3.9.7+
Fix from $1,600 2022-03-11
Alltube MEDIUM 6.1
CVE-2022-24739

alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redire…

Fix: 3.0.3+
Fix from $1,600 2022-03-08
Talk MEDIUM 6.1
CVE-2021-41180

Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the …

Fix: 12.1.2+
Fix from $1,600 2022-03-08
Archivy MEDIUM 6.1
CVE-2022-0697

Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.

Fix: 1.7.0+
Fix from $1,600 2022-03-06
Uri.js MEDIUM 6.1
CVE-2022-0868

Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.

Fix: 1.19.10+
Fix from $1,600 2022-03-06
Spirit MEDIUM 6.1
CVE-2022-0869

Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.

Fix: 0.12.3+
Fix from $1,600 2022-03-06
Dir 850l Firmware MEDIUM 6.1
CVE-2021-46379EPSS 16%

DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.

No fix yet
Fix from $1,600 2022-03-04
Openstack Platform MEDIUM 6.1
CVE-2021-3654EPSS 27%

A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

Fix: 21.2.3 / 22.2.3+
Fix from $1,600 2022-03-02
Cherwell Service Management MEDIUM 6.1
CVE-2022-26156

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= p…

Mitigation only
Fix from $1,600 2022-02-28
Cherwell Service Management MEDIUM 6.1
CVE-2022-26158

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a …

Mitigation only
Fix from $1,600 2022-02-28
Karma MEDIUM 6.1
CVE-2021-23495

The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.

Fix: 6.3.16+
Fix from $1,600 2022-02-25
Teamcity MEDIUM 6.1
CVE-2022-24330

In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.

Fix: 2021.2.1+
Fix from $1,600 2022-02-25
Oneview Global Dashboard MEDIUM 6.1
CVE-2021-29217

A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to…

Fix: 2.5+
Fix from $1,600 2022-02-24
Alltube MEDIUM 6.1
CVE-2022-0692

Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.

Fix: 3.0.1+
Fix from $1,600 2022-02-21
Gitlab Authentication MEDIUM 5.4
CVE-2022-25196

Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication pro…

Fix: after 1.13
Fix from $1,600 2022-02-15
Microweber MEDIUM 6.1
CVE-2022-0597

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

Fix: 1.2.11+
Fix from $1,600 2022-02-15
Noptin MEDIUM 6.1
CVE-2021-25033

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, lead…

Fix: 1.6.5+
Fix from $1,600 2022-02-14
Magnolia Cms HIGH 8.8
CVE-2021-46366

An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Fo…

Fix: 6.2.4+
Fix from $1,950 2022-02-11
Microweber MEDIUM 6.1
CVE-2022-0560

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

Fix: 1.2.11+
Fix from $1,600 2022-02-11
Xwiki MEDIUM 6.1
CVE-2022-23618

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is no protection …

Fix: after 13.3
Fix from $1,600 2022-02-09
Sinema Remote Connect Server MEDIUM 6.1
CVE-2022-23102EPSS 5%

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. …

Fix: after 2.0
Fix from $1,600 2022-02-09
Gitea MEDIUM 6.1
CVE-2021-45328

Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.

Fix: 1.4.3+
Fix from $1,600 2022-02-08
Octopus Deploy MEDIUM 6.1
CVE-2022-23184

In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.

Fix: 2021.2.8011 / 2021.3.11057+
Fix from $1,600 2022-02-07
Seeddms MEDIUM 6.1
CVE-2021-45408

Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using …

No fix yet
Fix from $1,600 2022-02-04
Axiomsl Controllerview MEDIUM 6.1
CVE-2022-22919

Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.

Fix: after 10.8.1
Fix from $1,600 2022-01-30
Plone MEDIUM 6.1
CVE-2022-23599

Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to vers…

Fix: 3.0.6+
Fix from $1,600 2022-01-28