Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Touchbase.ai MEDIUM 6.1
CVE-2020-26219

touchbase.ai before version 2.0 is vulnerable to Open Redirect. Impacts can be many, and vary from theft of information and credentials, to the redir…

Fix: 2.0+
Fix from $1,600 2020-11-11
Octopus Deploy MEDIUM 6.1
CVE-2020-26161

In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.

Fix: after 2020.4.2
Fix from $1,600 2020-10-26
Secure Firewall Management Center MEDIUM 6.1
CVE-2020-3558

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote atta…

Fix: after 6.5.0.4
Fix from $1,600 2020-10-21
Netweaver Application Server Java MEDIUM 6.1
CVE-2020-6365

SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to…

Mitigation only
Fix from $1,600 2020-10-15
Mmc\+ MEDIUM 6.1
CVE-2020-24551

IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to redirect to any malicious site a…

Mitigation only
Fix from $1,600 2020-10-14
Fluid Engine MEDIUM 6.1
CVE-2020-15241

TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripti…

Fix: 2.0.5 / 2.1.4+
Fix from $1,600 2020-10-08
Next.js MEDIUM 6.1
CVE-2020-15242

Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to all…

Fix: 9.5.4+
Fix from $1,600 2020-10-08
Firefox MEDIUM 6.1
CVE-2020-15677

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the …

Fix: 78.3 / 81.0+
Fix from $1,600 2020-10-01
Managed Services Accelerator MEDIUM 6.1
CVE-2019-15974

A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user t…

Fix: 3.7.0+
Fix from $1,600 2020-09-23
Control Desk HIGH 8.2
CVE-2020-4409

IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a vic…

Fix: 7.6.1.2+
Fix from $1,950 2020-09-16
Yodobashi MEDIUM 6.1
CVE-2020-5627

Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As…

Fix: after 1.8.7
Fix from $1,600 2020-09-09
Liferay Portal HIGH 7.5
CVE-2020-24554

The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote a…

Fix: 7.3.3+
Fix from $1,950 2020-09-01
Nitori MEDIUM 6.1
CVE-2020-5623

NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access a…

Fix: after 6.0.4
Fix from $1,600 2020-08-28
Joomla\! MEDIUM 6.1
CVE-2020-24598

An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.

Fix: 3.9.21+
Fix from $1,600 2020-08-26
Cybermail MEDIUM 6.1
CVE-2020-5541

Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attack…

Mitigation only
Fix from $1,600 2020-08-25
Ovirt Engine MEDIUM 5.3
CVE-2020-10775

An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary we…

Fix: after 4.4
Fix from $1,600 2020-08-24
Security Guardium Insights MEDIUM 6.1
CVE-2020-4598

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim…

Mitigation only
Fix from $1,600 2020-08-24
Planning Analytics MEDIUM 6.1
CVE-2020-4653

IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit …

Patch available
Fix from $1,600 2020-08-19
Kubernetes MEDIUM 6.8
CVE-2020-8559EPSS 6%

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect o…

Fix: 1.16.13 / 1.17.9+
Fix from $1,600 2020-07-22
Impact 360 MEDIUM 6.1
CVE-2019-12783

An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after …

No fix yet
Fix from $1,600 2020-07-14
Jira MEDIUM 6.1
CVE-2019-20901

The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a diffe…

Fix: 8.5.2+
Fix from $1,600 2020-07-13
Shirasagi MEDIUM 6.1
CVE-2020-5607

Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing at…

Fix: after 1.13.1
Fix from $1,600 2020-07-10
O2 Business MEDIUM 6.1
CVE-2020-11882

The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. The purpose of this activity is…

No fix yet
Fix from $1,600 2020-07-07
Oauth2 Proxy MEDIUM 5.4
CVE-2020-4037

In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to …

Fix: 6.0.0+
Fix from $1,600 2020-06-29
Mattermost Server MEDIUM 6.1
CVE-2017-18897

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action …

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18891

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Desktop MEDIUM 6.1
CVE-2020-14454

An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is…

Fix: 4.4.0+
Fix from $1,600 2020-06-19
Identity Server MEDIUM 6.1
CVE-2020-14446

An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.

Fix: after 5.10.0
Fix from $1,600 2020-06-18
Umbrella MEDIUM 6.1
CVE-2020-3337

A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The …

Mitigation only
Fix from $1,600 2020-06-18
WordPress MEDIUM 5.7
CVE-2020-4048

In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading …

Fix: 3.7.34 / 3.8.34+
Fix from $1,600 2020-06-12