Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Big Ip Advanced Web Application Firewall MEDIUM 6.1
CVE-2021-22984

On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before …

Fix: 11.6.5.2 / 12.1.5.2+
Fix from $1,600 2021-02-12
Rails MEDIUM 6.1
CVE-2021-22881EPSS 87%

The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` header…

Fix: 6.0.3.5 / 6.1.2.1+
Fix from $1,600 2021-02-11
Openemr MEDIUM 6.1
CVE-2020-13565

An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.…

No fix yet
Fix from $1,600 2021-02-10
Ui5 MEDIUM 6.1
CVE-2021-21476

SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a…

Fix: 1.38.49 / 1.52.49+
Fix from $1,600 2021-02-09
Web Dynpro Abap MEDIUM 6.1
CVE-2021-21478

SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

Mitigation only
Fix from $1,600 2021-02-09
B2evolution MEDIUM 6.1
CVE-2020-22840EPSS 14%

Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controll…

Fix: 6.11.6+
Fix from $1,600 2021-02-09
Hub MEDIUM 6.1
CVE-2021-25757

In JetBrains Hub before 2020.1.12629, an open redirect was possible.

Fix: 2020.1.12629+
Fix from $1,600 2021-02-03
Oauth2 Proxy MEDIUM 6.1
CVE-2021-21291

OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to vali…

Fix: 7.0.0+
Fix from $1,600 2021-02-02
Archer MEDIUM 5.4
CVE-2020-29537

Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users …

Fix: 6.6.0.8 / 6.7.0.8+
Fix from $1,600 2021-01-29
Mobile Application Platform MEDIUM 6.1
CVE-2020-1723

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected ver…

Mitigation only
Fix from $1,600 2021-01-28
Revive Adserver MEDIUM 6.1
CVE-2021-22873EPSS 70%

Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scri…

Fix: 5.1.0+
Fix from $1,600 2021-01-26
Smart Software Manager On Prem MEDIUM 5.4
CVE-2021-1218

A vulnerability in the web management interface of Cisco Smart Software Manager satellite could allow an authenticated, remote attacker to redirect a…

Fix: after 5.0
Fix from $1,600 2021-01-20
Firefox MEDIUM 6.1
CVE-2020-26979

When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then red…

Fix: 84.0+
Fix from $1,600 2021-01-07
Wyse Management Suite MEDIUM 6.1
CVE-2020-29498

Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attacker could potentially exploit …

Fix: 3.1+
Fix from $1,600 2021-01-04
Nhiservisignadapter HIGH 7.4
CVE-2020-25845

Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host,…

Mitigation only
Fix from $1,950 2020-12-31
Nhiservisignadapter HIGH 7.4
CVE-2020-25846

The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to …

Mitigation only
Fix from $1,950 2020-12-31
Autobahn MEDIUM 6.1
CVE-2020-35678

Autobahn|Python before 20.12.3 allows redirect header injection.

Fix: 20.12.3+
Fix from $1,600 2020-12-27
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2020-27729

In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an undisclosed link on the BIG-IP…

Fix: 13.1.3.5 / 14.1.3.1+
Fix from $1,600 2020-12-24
Security Secret Server MEDIUM 6.1
CVE-2020-4840

IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to v…

Patch available
Fix from $1,600 2020-12-21
Jupyter Server MEDIUM 6.1
CVE-2020-26275

The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, Jupyte…

Fix: 1.1.1+
Fix from $1,600 2020-12-21
Spiceworks MEDIUM 6.1
CVE-2020-25901EPSS 5%

Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host head…

No fix yet
Fix from $1,600 2020-12-18
Tivoli Netcool\/impact MEDIUM 6.1
CVE-2020-4849

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse t…

Fix: after 7.1.0.19
Fix from $1,600 2020-12-15
Solution Manager MEDIUM 6.1
CVE-2020-26836

SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability,…

No fix yet
Fix from $1,600 2020-12-09
Debian Linux MEDIUM 6.1
CVE-2020-29565

An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of v…

Fix: 15.3.2 / 16.2.1+
Fix from $1,600 2020-12-04
Kibana MEDIUM 6.1
CVE-2020-27816

The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the ori…

Fix: after 4.7
Fix from $1,600 2020-12-02
Jupyter Server MEDIUM 5.4
CVE-2020-26232

Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server could redirect the browser to …

Fix: 1.0.6+
Fix from $1,600 2020-11-24
Seeddms MEDIUM 6.1
CVE-2020-28726

Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.

Patch available
Fix from $1,600 2020-11-24
Suitecrm MEDIUM 6.1
CVE-2020-15300

SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.

Fix: after 7.11.13
Fix from $1,600 2020-11-18
Debian Linux MEDIUM 6.1
CVE-2020-26215

Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser …

Fix: 6.1.5+
Fix from $1,600 2020-11-18
Werkzeug MEDIUM 6.1
CVE-2020-28724

Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.

Fix: 0.11.6+
Fix from $1,600 2020-11-18