Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Wpforo Forum MEDIUM 6.1
CVE-2021-24406

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect…

Fix: 1.9.7+
Fix from $1,600 2021-07-06
Flask User MEDIUM 6.1
CVE-2021-23401

This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user t…

No fix yet
Fix from $1,600 2021-07-05
Collaboration MEDIUM 6.1
CVE-2021-34807

An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker wo…

Fix: 8.8.15+
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23182

The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious …

No fix yet
Fix from $1,600 2021-07-02
Powermux MEDIUM 6.1
CVE-2021-32721

PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to craft phishing links and othe…

Fix: 1.1.1+
Fix from $1,600 2021-06-29
Machform MEDIUM 6.1
CVE-2021-20105

Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.

Fix: 16+
Fix from $1,600 2021-06-29
Umbraco Cms MEDIUM 6.1
CVE-2021-34254

Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.

Fix: 7.15.7+
Fix from $1,600 2021-06-28
Aura Experience Portal MEDIUM 6.1
CVE-2021-25655

A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafte…

Fix: after 7.2.3
Fix from $1,600 2021-06-24
Getsimplecms MEDIUM 6.1
CVE-2020-18660

GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.

Fix: after 3.3.15
Fix from $1,600 2021-06-23
Gitpod MEDIUM 6.1
CVE-2021-35206

Gitpod before 0.6.0 allows unvalidated redirects.

Fix: 0.6.0+
Fix from $1,600 2021-06-22
Vanilla Forums MEDIUM 6.1
CVE-2010-4266

It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.

Fix: 2.0.10+
Fix from $1,600 2021-06-22
Webaccess\/scada MEDIUM 6.1
CVE-2021-32956

Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that c…

Fix: after 9.0.1
Fix from $1,600 2021-06-18
The Plus Addons For Elementor MEDIUM 6.1
CVE-2021-24358

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before …

Fix: 4.1.10+
Fix from $1,600 2021-06-14
Rails MEDIUM 6.1
CVE-2021-22903

The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certai…

Fix: 6.1.3.2+
Fix from $1,600 2021-06-11
Flask Unchained MEDIUM 5.4
CVE-2021-23393

This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation an…

Fix: 0.9.0+
Fix from $1,600 2021-06-11
Z Blogphp MEDIUM 6.1
CVE-2020-18268

Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "…

Fix: after 1.5.2
Fix from $1,600 2021-06-07
Bf 430 Firmware MEDIUM 6.1
CVE-2021-31252EPSS 29%

An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can…

No fix yet
Fix from $1,600 2021-06-04
Webex Meetings Online MEDIUM 6.1
CVE-2021-1525

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malici…

Fix: 3.0+
Fix from $1,600 2021-06-04
Dubbo MEDIUM 6.1
CVE-2021-25640

In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S…

Fix: 2.6.9 / 2.7.9+
Fix from $1,600 2021-06-01
Multi Tenant MEDIUM 6.1
CVE-2021-32645

Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirec…

Fix: 5.7.2+
Fix from $1,600 2021-05-27
Trailing Slash MEDIUM 6.1
CVE-2021-23387

The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerab…

Fix: 2.0.1+
Fix from $1,600 2021-05-24
Finesse MEDIUM 6.1
CVE-2021-1358

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undes…

Fix: after 12.6
Fix from $1,600 2021-05-22
Prometheus MEDIUM 6.1
CVE-2021-29622EPSS 20%

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seam…

Fix: 2.26.1+
Fix from $1,600 2021-05-19
Smartstorenet MEDIUM 6.1
CVE-2020-36365

Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Ed…

Fix: 4.1.0+
Fix from $1,600 2021-05-19
Flask Security MEDIUM 6.1
CVE-2021-32618

The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained versi…

Mitigation only
Fix from $1,600 2021-05-17
Koa Remove Trailing Slashes MEDIUM 5.4
CVE-2021-23384

The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing…

Fix: 2.0.2+
Fix from $1,600 2021-05-17
Acymailing MEDIUM 6.1
CVE-2021-24288

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a l…

Fix: 7.5.0+
Fix from $1,600 2021-05-17
Gui For Windows MEDIUM 6.1
CVE-2021-27612

In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain …

Mitigation only
Fix from $1,600 2021-05-11
Integrated Management Controller MEDIUM 6.1
CVE-2021-1397

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote…

Fix: 3.2+
Fix from $1,600 2021-05-06
Drupal MEDIUM 6.1
CVE-2020-13662

Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitra…

Fix: after 7.70
Fix from $1,600 2021-05-05