Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Mod Auth Mellon MEDIUM 6.1
CVE-2019-13038

mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target U…

Fix: after 0.14.2
Fix from $1,600 2019-06-29
Chrome MEDIUM 5.4
CVE-2019-5823

Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restriction…

Fix: 74.0.3729.108+
Fix from $1,600 2019-06-27
Moodle MEDIUM 6.1
CVE-2019-10133

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricte…

Fix: after 3.6.3
Fix from $1,600 2019-06-26
Security Access Manager MEDIUM 6.8
CVE-2019-4153

IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi…

Fix: after 9.0.6
Fix from $1,600 2019-06-25
Access Management MEDIUM 6.1
CVE-2017-14394

OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly valida…

Fix: after 13.5.1
Fix from $1,600 2019-06-19
Spring Security Oauth MEDIUM 5.4
CVE-2019-11269EPSS 9%

Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported vers…

Fix: 2.0.18 / 2.1.5+
Fix from $1,600 2019-06-12
Solutions Business Manager MEDIUM 6.1
CVE-2019-3477

Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.

Fix: 11.4.2+
Fix from $1,600 2019-06-07
Jazz For Service Management MEDIUM 6.1
CVE-2019-4201

IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.…

Fix: after 1.1.3.2
Fix from $1,600 2019-06-06
Fortios MEDIUM 6.1
CVE-2018-13384

A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially…

Fix: 6.0.5+
Fix from $1,600 2019-06-04
Galaxy S9 Firmware CRITICAL 9.3
CVE-2019-6741

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security …

Fix: 2019-01+
Fix from $2,300 2019-06-03
Odoo MEDIUM 5.4
CVE-2017-5871

Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).

No fix yet
Fix from $1,600 2019-05-22
Garoon MEDIUM 6.1
CVE-2019-5946

Open redirect vulnerability in Cybozu Garoon 4.2.4 to 4.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at…

Fix: after 4.10.1
Fix from $1,600 2019-05-17
GitLab HIGH 7.5
CVE-2019-6781

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 1…

Fix: 11.5.10 / 11.6.8+
Fix from $1,950 2019-05-17
GitLab MEDIUM 6.1
CVE-2019-10117

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A red…

Fix: 11.7.8 / 11.8.4+
Fix from $1,600 2019-05-16
Divar Ip 2000 Firmware MEDIUM 6.1
CVE-2019-8951

An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a …

Fix: 3.62.0019 / 3.70.0056+
Fix from $1,600 2019-05-13
Nas Os MEDIUM 6.1
CVE-2018-12300

Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'sta…

No fix yet
Fix from $1,600 2019-05-13
Revive Adserver MEDIUM 5.4
CVE-2019-5433

A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL th…

Fix: 4.2.0+
Fix from $1,600 2019-05-06
Intellect Core Banking MEDIUM 6.1
CVE-2018-14931

An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?I…

No fix yet
Fix from $1,600 2019-04-30
Storediq MEDIUM 6.1
CVE-2019-4166

IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a speciall…

Fix: after 7.6.0.18
Fix from $1,600 2019-04-30
Uaa Release MEDIUM 6.1
CVE-2019-3788

Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured w…

Fix: 71.0+
Fix from $1,600 2019-04-25
Micrologix 1400 A Firmware MEDIUM 6.1
CVE-2019-10955

In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earli…

Fix: after 30.014
Fix from $1,600 2019-04-25
Content Navigator MEDIUM 6.1
CVE-2019-4092

IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victi…

Mitigation only
Fix from $1,600 2019-04-25
Activematrix Bpm MEDIUM 6.1
CVE-2019-8995

The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distributi…

Fix: after 4.2.0
Fix from $1,600 2019-04-24
Search Guard MEDIUM 6.1
CVE-2018-20698

The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.

Fix: 6.3.0-16+
Fix from $1,600 2019-04-09
Elgg MEDIUM 6.1
CVE-2019-11016

Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.

Fix: 1.12.18 / 2.3.11+
Fix from $1,600 2019-04-08
Notebook MEDIUM 6.1
CVE-2019-10856

In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.

Fix: 5.7.8+
Fix from $1,600 2019-04-04
Qtest Manager MEDIUM 6.1
CVE-2018-15180

qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter.

No fix yet
Fix from $1,600 2019-04-02
Web Station MEDIUM 6.1
CVE-2018-8913

Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted U…

Fix: 2.1.3-0139+
Fix from $1,600 2019-04-01
Crowd MEDIUM 6.1
CVE-2017-18109

The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect…

Fix: 3.0.2+
Fix from $1,600 2019-03-29
Jupyterhub MEDIUM 6.1
CVE-2019-10255

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allow…

Fix: 0.9.5 / 5.7.7+
Fix from $1,600 2019-03-28