Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Fiori MEDIUM 5.4
CVE-2020-6266

SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation…

Mitigation only
Fix from $1,600 2020-06-10
Sharepoint Enterprise Server MEDIUM 6.1
CVE-2020-1323

An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link…

Patch available
Fix from $1,600 2020-06-09
Edge MEDIUM 6.1
CVE-2020-1220

A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromi…

Patch available
Fix from $1,600 2020-06-09
Mediawiki MEDIUM 6.1
CVE-2020-10959

resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML cont…

Fix: 1.35+
Fix from $1,600 2020-06-02
Knock Knock MEDIUM 6.1
CVE-2020-13486

The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.

Fix: 1.2.8+
Fix from $1,600 2020-05-25
Submitty MEDIUM 6.1
CVE-2020-13121

Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.

Fix: after 20.04.01
Fix from $1,600 2020-05-16
Concourse MEDIUM 6.1
CVE-2020-5409

Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could co…

Fix: 5.2.8 / 5.5.10+
Fix from $1,600 2020-05-14
Pan Os MEDIUM 6.1
CVE-2020-1997

An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection …

Fix: 7.1.26 / 8.0.14+
Fix from $1,600 2020-05-13
Direct Mail MEDIUM 6.1
CVE-2020-12699

The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.

Fix: after 5.2.3
Fix from $1,600 2020-05-13
Oauth2 Proxy MEDIUM 6.1
CVE-2020-11053

In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated u…

Fix: 5.1.1+
Fix from $1,600 2020-05-07
Secure Firewall Management Center MEDIUM 6.1
CVE-2020-3311

A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect …

Fix: 6.3.0+
Fix from $1,600 2020-05-06
Content Security Management Appliance MEDIUM 6.1
CVE-2020-3178

Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthen…

Fix: 13.6.0+
Fix from $1,600 2020-05-06
Fedora MEDIUM 6.1
CVE-2020-12666

macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.

Fix: 1.3.7+
Fix from $1,600 2020-05-05
Glpi MEDIUM 6.1
CVE-2020-11034EPSS 8%

In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is f…

Fix: 9.4.6+
Fix from $1,600 2020-05-05
Archer MEDIUM 6.1
CVE-2020-5337

RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit …

Fix: 6.7.0.1+
Fix from $1,600 2020-05-04
Connections MEDIUM 6.1
CVE-2019-4209

HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.

Patch available
Fix from $1,600 2020-05-01
Sourcegraph MEDIUM 6.1
CVE-2020-12283

Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/…

Fix: 3.15.1+
Fix from $1,600 2020-04-30
Prestashop MEDIUM 6.1
CVE-2020-5270

In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from th…

Fix: 1.7.6.5+
Fix from $1,600 2020-04-20
Openmrs MEDIUM 6.1
CVE-2020-5732

In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user…

Fix: after 2.9.0
Fix from $1,600 2020-04-17
Openmrs MEDIUM 6.1
CVE-2020-5733

In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated use…

Fix: after 2.9.0
Fix from $1,600 2020-04-17
Ca Api Developer Portal MEDIUM 6.1
CVE-2020-11665

CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect…

Fix: after 4.3.1
Fix from $1,600 2020-04-15
Ca Api Developer Portal MEDIUM 6.1
CVE-2020-11663

CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.

Fix: after 4.3.1
Fix from $1,600 2020-04-15
Ca Api Developer Portal MEDIUM 6.1
CVE-2020-11664

CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect …

Fix: after 4.3.1
Fix from $1,600 2020-04-15
Vrealize Log Insight MEDIUM 6.1
CVE-2020-3954

Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

Fix: 8.1.0+
Fix from $1,600 2020-04-15
Businessobjects Business Intelligence Platform MEDIUM 6.1
CVE-2020-6211

SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to …

Mitigation only
Fix from $1,600 2020-04-14
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2020-6215

SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker…

No fix yet
Fix from $1,600 2020-04-14
Businessobjects Business Intelligence Platform MEDIUM 6.1
CVE-2020-6223

The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to incl…

Mitigation only
Fix from $1,600 2020-04-14
Stormshield Network Security MEDIUM 6.1
CVE-2020-8430

Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the atta…

Fix: after 4.0.1
Fix from $1,600 2020-04-13
Cross Domain Local Storage MEDIUM 6.1
CVE-2020-11611

An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOri…

Fix: after 2.0.5
Fix from $1,600 2020-04-07
Seo MEDIUM 6.1
CVE-2020-11515

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site…

Fix: after 1.0.40.2
Fix from $1,600 2020-04-07