Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Zulip Server MEDIUM 6.1
CVE-2019-19775

The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.

Fix: 2.0.8+
Fix from $1,600 2019-12-18
Keycloak MEDIUM 6.1
CVE-2014-3652

JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.

Patch available
Fix from $1,600 2019-12-15
Debian Linux MEDIUM 6.1
CVE-2019-19709

MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-…

Fix: after 1.33.1
Fix from $1,600 2019-12-11
Visual Studio 2019 MEDIUM 6.1
CVE-2019-1486

A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specifie…

Fix: 1.0.1374+
Fix from $1,600 2019-12-10
Ktor MEDIUM 6.1
CVE-2019-19703

In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.

Fix: after 1.2.6
Fix from $1,600 2019-12-10
Erlang\/otp MEDIUM 6.1
CVE-2016-1000107

inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted …

Fix: after 22.1
Fix from $1,600 2019-12-10
Debian Linux MEDIUM 6.1
CVE-2016-1000108

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the pr…

Fix: 2.0.4+
Fix from $1,600 2019-12-10
Python MEDIUM 6.1
CVE-2016-1000110

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote …

Fix: 2.7.13 / 3.3.7+
Fix from $1,600 2019-11-27
GitLab MEDIUM 6.1
CVE-2019-18451

An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redi…

Fix: after 12.4.0
Fix from $1,600 2019-11-26
Anti Virus MEDIUM 6.1
CVE-2019-15688

Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Se…

Fix: after 2020
Fix from $1,600 2019-11-26
Mod Auth Openidc MEDIUM 6.1
CVE-2019-14857

A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in …

Fix: 2.4.0.1+
Fix from $1,600 2019-11-26
Posh MEDIUM 6.1
CVE-2014-2213

Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web …

Fix: after 3.2.1
Fix from $1,600 2019-11-22
Mail2000 MEDIUM 6.1
CVE-2019-15073

An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authenticati…

Fix: after 7.0
Fix from $1,600 2019-11-20
Blackboard Learn MEDIUM 6.1
CVE-2018-13257

The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authenti…

No fix yet
Fix from $1,600 2019-11-18
Popojicms MEDIUM 6.1
CVE-2019-18815

PopojiCMS 2.0.1 allows refer= Open Redirection.

No fix yet
Fix from $1,600 2019-11-07
Drupal MEDIUM 6.1
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

Fix: 5.22 / 6.16+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 5.4
CVE-2010-3669

TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.

Fix: 4.2.13 / 4.3.4+
Fix from $1,600 2019-11-04
TYPO3 MEDIUM 6.1
CVE-2010-3661

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.

Fix: 4.1.14 / 4.2.13+
Fix from $1,600 2019-11-01
Security Directory Server HIGH 8.2
CVE-2019-4538

IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim …

Patch available
Fix from $1,950 2019-10-02
Youtrack MEDIUM 6.1
CVE-2019-15041

JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sp…

Fix: 2019.1.52545+
Fix from $1,600 2019-10-01
HTTP Server MEDIUM 6.1
CVE-2019-10098EPSS 74%

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded new…

Fix: after 2.4.39
Fix from $1,600 2019-09-25
Adas MEDIUM 6.1
CVE-2019-14912

An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks th…

No fix yet
Fix from $1,600 2019-09-20
Ubuntu Linux MEDIUM 6.1
CVE-2019-16393

SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.

Fix: 3.1.11 / 3.2.5+
Fix from $1,600 2019-09-17
Apeosware Management Suite MEDIUM 6.1
CVE-2019-6004

Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow re…

Fix: after 2.1.2.4
Fix from $1,600 2019-09-12
Shirasagi MEDIUM 6.1
CVE-2019-6009

Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing att…

Fix: after 1.7.0
Fix from $1,600 2019-09-12
Garoon MEDIUM 6.1
CVE-2019-5978

Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at…

Fix: after 4.10.2
Fix from $1,600 2019-09-12
WordPress MEDIUM 6.1
CVE-2019-16220

In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect i…

Fix: 5.2.3+
Fix from $1,600 2019-09-11
Alfresco MEDIUM 6.1
CVE-2019-14223

An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open …

Fix: 5.2.6+
Fix from $1,600 2019-09-06
Wp Private Content Plus HIGH 7.5
CVE-2019-15816

The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions.

Fix: 2.0+
Fix from $1,950 2019-08-30
Simple 301 Redirects MEDIUM 6.1
CVE-2019-15818

The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or act…

Fix: after 1.2.4
Fix from $1,600 2019-08-30