Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Login Or Logout Menu Item MEDIUM 6.1
CVE-2019-15820

The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication.

Fix: 1.2.0+
Fix from $1,600 2019-08-30
Components For Wp Bakery Page Builder MEDIUM 6.1
CVE-2019-15771

The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

Fix: 6.0+
Fix from $1,600 2019-08-29
Donations MEDIUM 6.1
CVE-2019-15772

The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

Fix: 1.4+
Fix from $1,600 2019-08-29
Travel Management MEDIUM 6.1
CVE-2019-15773

The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

Fix: 1.7+
Fix from $1,600 2019-08-29
Booking MEDIUM 6.1
CVE-2019-15774

The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

Fix: 2.5+
Fix from $1,600 2019-08-29
Learning Courses MEDIUM 6.1
CVE-2019-15775

The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

Fix: 4.8+
Fix from $1,600 2019-08-29
Simple 301 Redirects Addon Bulk Uploader MEDIUM 6.1
CVE-2019-15776

The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.

Fix: 1.2.5+
Fix from $1,600 2019-08-29
Fireware MEDIUM 6.1
CVE-2016-6154

The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).

Fix: after 11.11
Fix from $1,600 2019-08-23
Httpie HIGH 8.8
CVE-2019-10751

All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with sup…

No fix yet
Fix from $1,950 2019-08-23
Jira Server MEDIUM 6.1
CVE-2019-11589

The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.…

Fix: 7.13.6 / 8.2.3+
Fix from $1,600 2019-08-23
Search Guard MEDIUM 6.1
CVE-2019-13422

Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious…

Fix: 5.6.8-7 / 6.2.3-12+
Fix from $1,600 2019-08-23
Jira MEDIUM 6.1
CVE-2019-11585

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows r…

Fix: 7.13.6 / 8.2.3+
Fix from $1,600 2019-08-23
Webex Meetings Server MEDIUM 6.1
CVE-2019-1954

A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redi…

Fix: 4.0+
Fix from $1,600 2019-08-08
Gitlab Oauth MEDIUM 6.1
CVE-2019-10372

An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users…

Fix: after 1.4
Fix from $1,600 2019-08-07
Cpanel MEDIUM 6.1
CVE-2016-10769

cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).

Fix: 11.54.0.33 / 56.0.39+
Fix from $1,600 2019-08-05
Cpanel MEDIUM 5.0
CVE-2017-18441

cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel HIGH 7.4
CVE-2017-18414

cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).

Fix: 56.0.52 / 60.0.48+
Fix from $1,950 2019-08-02
Happypoint HIGH 8.1
CVE-2019-9140

When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascrip…

Mitigation only
Fix from $1,950 2019-08-01
Cpanel MEDIUM 6.1
CVE-2018-20929

cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).

Fix: 62.0.42 / 68.0.33+
Fix from $1,600 2019-08-01
Cpanel MEDIUM 6.1
CVE-2018-20867

cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).

Fix: 76.0.8+
Fix from $1,600 2019-07-30
Ash Aio MEDIUM 6.1
CVE-2019-1020016

ASH-AIO before 2.0.0.3 allows an open redirect.

No fix yet
Fix from $1,600 2019-07-29
Sg200 50 Firmware MEDIUM 6.1
CVE-2019-1943EPSS 11%

A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attack…

Mitigation only
Fix from $1,600 2019-07-17
Bable\ MEDIUM 6.1
CVE-2019-1010290

Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "n…

Fix: after 0.4.1
Fix from $1,600 2019-07-16
Asp.net Core MEDIUM 6.1
CVE-2019-1075

A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.

Patch available
Fix from $1,600 2019-07-15
Eventum MEDIUM 6.1
CVE-2018-12621

An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.

Mitigation only
Fix from $1,600 2019-07-05
Joruri Mail MEDIUM 6.1
CVE-2019-5965

Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing at…

Fix: after 2.1.4
Fix from $1,600 2019-07-05
Growi MEDIUM 6.1
CVE-2019-5969

Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks …

Fix: after 3.4.6
Fix from $1,600 2019-07-05
Blogengine.net MEDIUM 6.1
CVE-2019-10721

BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Securit…

Patch available
Fix from $1,600 2019-07-03
Read The Docs MEDIUM 6.1
CVE-2019-13175

Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addit…

Fix: 3.5.1+
Fix from $1,600 2019-07-02
Enterprise MEDIUM 6.1
CVE-2019-7275EPSS 9%

Optergy Proton/Enterprise devices allow Open Redirect.

Fix: after 2.3.0a
Fix from $1,600 2019-07-01