Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Opnsense MEDIUM 6.1
CVE-2020-23015

An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user t…

Fix: after 20.1.5
Fix from $1,600 2021-05-03
Airwave MEDIUM 6.1
CVE-2021-29137

A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches f…

Fix: 8.2.12.1+
Fix from $1,600 2021-04-29
Wget MEDIUM 6.1
CVE-2021-31879

GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.

Fix: after 1.21.1
Fix from $1,600 2021-04-29
Homeautomation MEDIUM 6.1
CVE-2020-21998

In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect user…

No fix yet
Fix from $1,600 2021-04-27
Superset MEDIUM 6.1
CVE-2021-28125EPSS 64%

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open re…

Fix: after 1.0.1
Fix from $1,600 2021-04-27
Authelia MEDIUM 5.4
CVE-2021-29456

Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on (SSO) for your applications v…

Fix: 4.28.0+
Fix from $1,600 2021-04-21
Fedora MEDIUM 6.3
CVE-2021-21392

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.28.0+
Fix from $1,600 2021-04-12
Phastpress MEDIUM 6.1
CVE-2021-24210

There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and …

Fix: 1.111+
Fix from $1,600 2021-04-05
Ninja Forms MEDIUM 6.1
CVE-2021-24165

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the u…

Fix: 3.4.34+
Fix from $1,600 2021-04-05
Macos Server MEDIUM 6.1
CVE-2020-9995

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Server 5.11. Processin…

Fix: 5.11+
Fix from $1,600 2021-04-02
Pomerium MEDIUM 6.1
CVE-2021-29651

Pomerium before 0.13.4 has an Open Redirect (issue 1 of 2).

Fix: 0.13.4+
Fix from $1,600 2021-04-02
Pomerium MEDIUM 6.1
CVE-2021-29652

Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process

Fix: after 0.13.3
Fix from $1,600 2021-04-02
Find MEDIUM 6.1
CVE-2020-24550

An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect paramet…

Fix: 13.2.7+
Fix from $1,600 2021-03-31
Ilch Cms MEDIUM 5.4
CVE-2021-27352

An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.

No fix yet
Fix from $1,600 2021-03-29
Tableau Server MEDIUM 6.1
CVE-2021-1629

Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.

Fix: 2019.4.18 / 2020.1.15+
Fix from $1,600 2021-03-26
Epolicy Orchestrator MEDIUM 6.3
CVE-2021-23888

Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user…

Fix: 5.10.0+
Fix from $1,600 2021-03-26
Appstore MEDIUM 6.1
CVE-2020-12483

The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructe…

Fix: 8.12.0.0+
Fix from $1,600 2021-03-23
Omero.web MEDIUM 5.4
CVE-2021-21377

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL af…

Fix: 5.9.0+
Fix from $1,600 2021-03-23
TYPO3 MEDIUM 6.1
CVE-2021-21338

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been…

Fix: 6.2.57 / 7.6.51+
Fix from $1,600 2021-03-23
Moodle MEDIUM 6.1
CVE-2019-14830

A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint conta…

Fix: after 3.7.1
Fix from $1,600 2021-03-19
Moodle MEDIUM 6.1
CVE-2019-14831

A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained a…

Fix: after 3.7.1
Fix from $1,600 2021-03-19
Netweaver Application Server Java MEDIUM 6.1
CVE-2021-21491

SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attack…

Mitigation only
Fix from $1,600 2021-03-10
I Net Clear Reports MEDIUM 6.1
CVE-2020-28150

I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user s…

No fix yet
Fix from $1,600 2021-03-09
Products.pluggableauthservice MEDIUM 6.1
CVE-2021-21337EPSS 8%

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t…

Fix: 2.6.1+
Fix from $1,600 2021-03-08
Pollbot MEDIUM 6.1
CVE-2021-21354

Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release p…

Fix: 1.4.4+
Fix from $1,600 2021-03-08
Fedora MEDIUM 6.1
CVE-2021-21273

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.25.0+
Fix from $1,600 2021-02-26
Debian Linux MEDIUM 6.1
CVE-2021-21330

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerabili…

Fix: 3.7.4+
Fix from $1,600 2021-02-26
Slashify MEDIUM 6.1
CVE-2021-3189

The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring.

No fix yet
Fix from $1,600 2021-02-19
Askey Rtf8115vw Firmware MEDIUM 6.1
CVE-2021-27404

Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.

No fix yet
Fix from $1,600 2021-02-19
Mbconnect24 MEDIUM 6.1
CVE-2020-35560

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.

Fix: after 2.6.2
Fix from $1,600 2021-02-16