Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Event Tickets MEDIUM 6.1
CVE-2021-25028

The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given va…

Fix: 5.2.2+
Fix from $1,600 2022-01-24
Webp Converter For Media MEDIUM 6.1
CVE-2021-25074

The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirectin…

Fix: 4.0.3+
Fix from $1,600 2022-01-24
Anycomment MEDIUM 6.1
CVE-2021-24838

The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function wit…

Fix: 0.3.5+
Fix from $1,600 2022-01-17
Debian Linux MEDIUM 6.1
CVE-2022-0235

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Fix: 1.0 / 2.6.7+
Fix from $1,600 2022-01-16
Qcalagent MEDIUM 6.1
CVE-2021-38678

An open redirect vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows attackers to redire…

Fix: 1.1.7+
Fix from $1,600 2022-01-14
Rails MEDIUM 6.1
CVE-2021-44528

A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with c…

Patch available
Fix from $1,600 2022-01-10
Forge MEDIUM 6.1
CVE-2022-0122

forge is vulnerable to URL Redirection to Untrusted Site

Fix: 1.0.0+
Fix from $1,600 2022-01-06
Shopware MEDIUM 6.1
CVE-2022-21651

Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to…

Fix: 5.7.7+
Fix from $1,600 2022-01-05
Groupsession MEDIUM 6.1
CVE-2021-20875

Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.…

Fix: after 5.1.1
Fix from $1,600 2021-12-24
Gim MEDIUM 6.1
CVE-2021-40852

TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the atta…

Mitigation only
Fix from $1,600 2021-12-17
Nextjs Auth0 MEDIUM 6.1
CVE-2021-43812

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain retu…

Fix: 1.6.2+
Fix from $1,600 2021-12-16
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2020-18985

An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their c…

Mitigation only
Fix from $1,600 2021-12-15
Openwhyd MEDIUM 6.1
CVE-2021-3829

openwhyd is vulnerable to URL Redirection to Untrusted Site

Fix: 1.45.3+
Fix from $1,600 2021-12-10
Firefox MEDIUM 6.1
CVE-2021-43532

The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows -…

Fix: 94.0+
Fix from $1,600 2021-12-08
Fortiweb MEDIUM 6.1
CVE-2021-43064

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below…

Fix: after 6.3.15
Fix from $1,600 2021-12-08
Fortiweb MEDIUM 5.4
CVE-2021-36191

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the devic…

Fix: after 6.3.15
Fix from $1,600 2021-12-08
Showdoc MEDIUM 6.1
CVE-2021-4000

showdoc is vulnerable to URL Redirection to Untrusted Site

Patch available
Fix from $1,600 2021-12-03
Showdoc MEDIUM 6.1
CVE-2021-3989

showdoc is vulnerable to URL Redirection to Untrusted Site

Fix: 2.9.13+
Fix from $1,600 2021-12-01
Cryptshare Server MEDIUM 5.4
CVE-2021-42564

An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confi…

Fix: 5.1.0+
Fix from $1,600 2021-11-30
Redash MEDIUM 6.1
CVE-2021-43777

Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly …

Fix: after 10.0.0
Fix from $1,600 2021-11-24
Chrome MEDIUM 6.1
CVE-2021-38000 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily brow…

Fix: 95.0.4638.69+
Fix from $1,600 2021-11-23
Emc Cloud Link MEDIUM 5.4
CVE-2021-36332

Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentiall…

Fix: 7.1.1+
Fix from $1,600 2021-11-23
Oppia MEDIUM 6.1
CVE-2021-41733

Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.

Patch available
Fix from $1,600 2021-11-08
Collaboration Meeting Rooms MEDIUM 6.1
CVE-2021-1500

A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to…

Fix: 2021.10.18.2439m+
Fix from $1,600 2021-11-04
Replicated Classic MEDIUM 6.1
CVE-2021-43058

An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exploit this vulnerability, an a…

Fix: 2.53.1+
Fix from $1,600 2021-11-01
Firepower Management Center Virtual Appliance MEDIUM 6.1
CVE-2021-34764

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute…

Fix: 6.4.0.13 / 6.6.5+
Fix from $1,600 2021-10-27
Firefly Iii MEDIUM 5.4
CVE-2021-3851

firefly-iii is vulnerable to URL Redirection to Untrusted Site

Fix: 5.6.2+
Fix from $1,600 2021-10-19
Rails MEDIUM 6.1
CVE-2021-22942

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a…

Fix: 6.0.4.1 / 6.1.4.1+
Fix from $1,600 2021-10-18
Fastify Static MEDIUM 6.1
CVE-2021-22963

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double sl…

Fix: 4.2.4+
Fix from $1,600 2021-10-14
Fastify Static HIGH 8.8
CVE-2021-22964

A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arb…

Fix: 4.4.1+
Fix from $1,950 2021-10-14