Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Unclassified CRITICAL 9.6
CVE-2026-53662

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (X…

Patch available
Fix from $2,300 2026-06-23
Nuxt MEDIUM 6.1
CVE-2026-56326

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validat…

Fix: 3.21.7 / 4.4.7+
Fix from $1,600 2026-06-22
Nuxt MEDIUM 6.1
CVE-2026-56697

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass th…

Fix: 3.21.7 / 4.4.7+
Fix from $1,600 2026-06-22
Webob MEDIUM 6.1
CVE-2026-44889

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerabl…

Fix: 1.8.10+
Fix from $1,600 2026-06-22
Authlib MEDIUM 5.4
CVE-2026-41479

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can …

Fix: 1.6.10+
Fix from $1,600 2026-06-22
Aiohttp MEDIUM 6.1
CVE-2026-54276

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication resp…

Fix: 3.14.1+
Fix from $1,600 2026-06-22
Unclassified MEDIUM 5.1
CVE-2026-12863

An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.

Mitigation only
Fix from $1,600 2026-06-22
365 Copilot HIGH 8.8
CVE-2026-47645

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges ov…

Mitigation only
Fix from $1,950 2026-06-19
Gridtime 3000 Firmware MEDIUM 5.4
CVE-2026-12622

The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from…

Fix: 1.2r0.0+
Fix from $1,600 2026-06-19
Apisix HIGH 7.2
CVE-2026-48895

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an …

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Apisix MEDIUM 6.1
CVE-2026-44915

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulner…

Fix: 3.17.0+
Fix from $1,600 2026-06-19
Pgadmin 4 MEDIUM 6.1
CVE-2026-12049

Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form p…

Fix: 9.16+
Fix from $1,600 2026-06-19
Unclassified HIGH 8.8
CVE-2026-55237

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 h…

Mitigation only
Fix from $1,950 2026-06-18
Powerflex Rack Release Certification Matrix MEDIUM 6.1
CVE-2025-32748

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access…

Fix: 3.8.4.1 / 3.9.1.1+
Fix from $1,600 2026-06-17
Unclassified MEDIUM 5.1
CVE-2026-10839

Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the …

Mitigation only
Fix from $1,600 2026-06-17
Unclassified MEDIUM 5.1
CVE-2026-10837

Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that, w…

Mitigation only
Fix from $1,600 2026-06-17
Human Resources HIGH 7.5
CVE-2026-46955

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected are 12.2.3-…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Isupplier Portal HIGH 8.0
CVE-2026-46894

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affected are 12.…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Webcenter Content HIGH 8.2
CVE-2026-46806

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect…

Mitigation only
Fix from $1,950 2026-06-17
Webcenter Sites HIGH 8.0
CVE-2026-46796

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected a…

Mitigation only
Fix from $1,950 2026-06-17
Weblogic Server HIGH 8.3
CVE-2026-35302

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 a…

Mitigation only
Fix from $1,950 2026-06-17
Weblogic Server HIGH 8.8
CVE-2026-35259

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 a…

Mitigation only
Fix from $1,950 2026-06-17
Weblogic Server HIGH 8.7
CVE-2026-35258

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 a…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified MEDIUM 6.8
CVE-2026-53523

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRe…

Mitigation only
Fix from $1,600 2026-06-12
Iam\/sso Gateway MEDIUM 6.1
CVE-2026-50089

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," wit…

No fix yet
Fix from $1,600 2026-06-12
Umbraco Cms MEDIUM 6.1
CVE-2026-46616

Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operati…

Fix: 13.14.0 / 17.4.0+
Fix from $1,600 2026-06-10
Erlang\/inets MEDIUM 6.5
CVE-2026-48856

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards…

Fix: 9.3.2.6 / 9.6.2.2+
Fix from $1,600 2026-06-10
Unclassified MEDIUM 6.1
CVE-2026-45566

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next…

No fix yet
Fix from $1,600 2026-06-10
Spring Security MEDIUM 6.1
CVE-2026-41706

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be r…

Fix: 5.7.24 / 5.8.26+
Fix from $1,600 2026-06-10
Spring Security MEDIUM 6.1
CVE-2026-41008

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a …

Fix: 1.5.7.1 / 7.0.5.1+
Fix from $1,600 2026-06-10