Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Remote Service Manager MEDIUM 6.1
CVE-2021-20806

Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phis…

Fix: after 3.1.9
Fix from $1,600 2021-10-13
Sonicos MEDIUM 6.1
CVE-2021-20031EPSS 13%

A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domain…

Fix: after 7.0.1-r1283
Fix from $1,600 2021-10-12
Orbital MEDIUM 6.1
CVE-2021-34772

A vulnerability in the web-based management interface of Cisco Orbital could allow an unauthenticated, remote attacker to redirect users to a malicio…

Mitigation only
Fix from $1,600 2021-10-06
Ngeniusone MEDIUM 5.4
CVE-2021-35205

NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector.

Mitigation only
Fix from $1,600 2021-09-30
Placeos Authentication MEDIUM 6.1
CVE-2021-41826EPSS 12%

PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.

Fix: 1.29.10.0+
Fix from $1,600 2021-09-30
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2021-23052

On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM acce…

Fix: 14.1.4.4+
Fix from $1,600 2021-09-14
Access Manager MEDIUM 6.1
CVE-2021-22526

Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

Fix: 4.5.4 / 5.0.1+
Fix from $1,600 2021-09-13
Clearance MEDIUM 6.1
CVE-2021-23435

This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If th…

Fix: 2.5.0+
Fix from $1,600 2021-09-12
Flask Appbuilder MEDIUM 6.1
CVE-2021-32805

Flask-AppBuilder is an application development framework, built on top of Flask. In affected versions if using Flask-AppBuilder OAuth, an attacker ca…

Fix: 3.3.2+
Fix from $1,600 2021-09-08
Eyoucms MEDIUM 6.1
CVE-2021-39501

EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.

No fix yet
Fix from $1,600 2021-09-07
Network Automation MEDIUM 6.1
CVE-2021-38123

Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02…

Mitigation only
Fix from $1,600 2021-09-07
Fedora MEDIUM 6.1
CVE-2021-39191

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenti…

Fix: 2.4.9.4+
Fix from $1,600 2021-09-03
Nested Pages MEDIUM 6.1
CVE-2021-38343

The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `n…

Fix: after 3.1.15
Fix from $1,600 2021-08-30
Ipad Os HIGH 7.4
CVE-2021-30888

An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvO…

Fix: 8.1 / 12.0.1+
Fix from $1,950 2021-08-24
Nagios Xi MEDIUM 6.1
CVE-2021-37352EPSS 6%

An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could …

Fix: 5.8.5+
Fix from $1,600 2021-08-13
Next.js MEDIUM 6.1
CVE-2021-37699

Next.js is an open source website development framework to be used with the React library. In affected versions specially encoded paths could be used…

Fix: after 11.0.1
Fix from $1,600 2021-08-12
Cf Deployment MEDIUM 6.1
CVE-2021-22098

UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by…

Fix: 16.20.0 / 75.5.0+
Fix from $1,600 2021-08-11
Netweaver Knowledge Management MEDIUM 6.1
CVE-2021-33707

SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a…

No fix yet
Fix from $1,600 2021-08-10
Digital Experience Platform MEDIUM 6.1
CVE-2021-33331

Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix…

Fix: 7.3.2+
Fix from $1,600 2021-08-03
Emc Idrac9 Firmware MEDIUM 6.1
CVE-2021-21579

Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability…

Fix: 4.40.40.00+
Fix from $1,600 2021-08-03
Emc Idrac9 Firmware MEDIUM 6.1
CVE-2021-21578

Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability…

Fix: 4.40.40.00+
Fix from $1,600 2021-08-03
Isurlinportal MEDIUM 6.1
CVE-2021-32806

Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal prior to 1.2.0 have an Open Redirect vu…

Fix: 1.2.0+
Fix from $1,600 2021-08-02
Fedora MEDIUM 6.1
CVE-2021-37746

textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accept…

Fix: 3.18.0+
Fix from $1,600 2021-07-30
Groupsession MEDIUM 6.1
CVE-2021-20789

Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3…

Fix: 5.1.0+
Fix from $1,600 2021-07-30
Emc Avamar Server MEDIUM 6.1
CVE-2020-5329

Dell EMC Avamar Server contains an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect applicat…

Patch available
Fix from $1,600 2021-07-29
Url Parse MEDIUM 5.3
CVE-2021-3664

url-parse is vulnerable to URL Redirection to Untrusted Site

Fix: 1.5.2+
Fix from $1,600 2021-07-26
Fedora MEDIUM 6.1
CVE-2021-32786

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenti…

Fix: 2.4.9+
Fix from $1,600 2021-07-22
Orca Hcm MEDIUM 6.1
CVE-2021-35966

The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to…

Fix: after 10.0
Fix from $1,600 2021-07-19
Uri.js MEDIUM 6.1
CVE-2021-3647

URI.js is vulnerable to URL Redirection to Untrusted Site

Fix: 1.19.7+
Fix from $1,600 2021-07-16
Jamf MEDIUM 6.1
CVE-2021-35037

Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An…

Fix: 10.30.1+
Fix from $1,600 2021-07-12