Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Stormshield Network Security MEDIUM 6.1
CVE-2020-8430

Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the atta…

Fix: after 4.0.1
Fix from $1,600 2020-04-13
Cross Domain Local Storage MEDIUM 6.1
CVE-2020-11611

An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOri…

Fix: after 2.0.5
Fix from $1,600 2020-04-07
Seo MEDIUM 6.1
CVE-2020-11515

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site…

Fix: after 1.0.40.2
Fix from $1,600 2020-04-07
Grav MEDIUM 6.1
CVE-2020-11529EPSS 11%

Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.

Fix: after 1.6.31
Fix from $1,600 2020-04-04
Revive Adserver MEDIUM 6.1
CVE-2020-8143EPSS 70%

An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could tr…

Fix: 5.0.5+
Fix from $1,600 2020-04-03
HTTP Server MEDIUM 6.1
CVE-2020-1927EPSS 57%

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded new…

Fix: after 2.4.41
Fix from $1,600 2020-04-02
Centreon MEDIUM 6.1
CVE-2019-19484

Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.

Fix: after 19.04.4
Fix from $1,600 2020-03-20
Moodle MEDIUM 6.1
CVE-2019-14882

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

Fix: after 3.7.3
Fix from $1,600 2020-03-18
Raquest MEDIUM 5.2
CVE-2019-19613

An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing …

Mitigation only
Fix from $1,600 2020-03-16
Fortios MEDIUM 6.1
CVE-2019-6696

An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an…

Fix: after 6.0.8
Fix from $1,600 2020-03-15
Webthings Gateway MEDIUM 6.1
CVE-2020-6803

An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.

Fix: 2020-02-26+
Fix from $1,600 2020-02-28
Sterling B2b Integrator MEDIUM 6.1
CVE-2019-4595

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing attacks, using an open redirec…

Fix: after 5.2.6.5
Fix from $1,600 2020-02-24
Debian Linux MEDIUM 6.1
CVE-2019-20479

A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.

Fix: 2.4.1+
Fix from $1,600 2020-02-20
Netsweeper MEDIUM 6.1
CVE-2014-9617EPSS 8%

Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web…

Fix: 4.0.5+
Fix from $1,600 2020-02-19
Ez Media \& Backup Center Ix2 Firmware MEDIUM 6.1
CVE-2019-19758

A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated,…

Fix: after 4.1.406.34763
Fix from $1,600 2020-02-14
Telaen MEDIUM 6.1
CVE-2013-2621EPSS 11%

Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a…

Fix: 1.3.1+
Fix from $1,600 2020-02-03
Oauth2 Proxy MEDIUM 6.1
CVE-2020-5233

OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched i…

Fix: 5.0.0+
Fix from $1,600 2020-01-30
Secure Entry Server MEDIUM 6.1
CVE-2013-2764

Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_A…

Fix: 4.7.0+
Fix from $1,600 2020-01-28
Security Secret Server MEDIUM 6.1
CVE-2019-4631

IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to v…

Fix: 10.7.000059+
Fix from $1,600 2020-01-28
Plone MEDIUM 6.1
CVE-2020-7936

An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, wh…

Fix: after 5.2.1
Fix from $1,600 2020-01-23
Wechat MEDIUM 5.4
CVE-2019-17151

This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent WeChat Prior to 7.0.9. User in…

Fix: 7.0.9+
Fix from $1,600 2020-01-07
Chamilo Lms MEDIUM 6.1
CVE-2015-9540

Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.

Fix: after 1.9.10.2
Fix from $1,600 2020-01-04
Mybb MEDIUM 6.1
CVE-2019-20225

MyBB before 1.8.22 allows an open redirect on login.

Fix: 1.8.22+
Fix from $1,600 2020-01-02
Movable Type MEDIUM 6.1
CVE-2019-6025

Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable …

Fix: after 7.1.3
Fix from $1,600 2019-12-26
Athenz MEDIUM 6.1
CVE-2019-6035

Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac…

Fix: after 1.8.24
Fix from $1,600 2019-12-26
Powercms MEDIUM 6.1
CVE-2019-6020

Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows…

Fix: after 5.12
Fix from $1,600 2019-12-26
Limedio MEDIUM 6.1
CVE-2019-6021

Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web …

Mitigation only
Fix from $1,600 2019-12-26
Crushftp MEDIUM 6.1
CVE-2018-18288

CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.

Fix: after 8.3.0
Fix from $1,600 2019-12-26
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2019-18781

An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click …

Mitigation only
Fix from $1,600 2019-12-18
Shazam MEDIUM 6.1
CVE-2019-8791

An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Vers…

Fix: 9.25.0 / 12.11.0+
Fix from $1,600 2019-12-18