Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Mod Auth Mellon MEDIUM 6.1
CVE-2019-3877

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by a…

Fix: 0.14.2+
Fix from $1,600 2019-03-27
Moodle MEDIUM 6.1
CVE-2019-3850

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (…

Fix: 3.1.17 / 3.4.8+
Fix from $1,600 2019-03-26
Content Navigator MEDIUM 5.4
CVE-2019-4035

IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, the…

Mitigation only
Fix from $1,600 2019-03-22
Getsimplecms MEDIUM 6.1
CVE-2019-9915

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

Mitigation only
Fix from $1,600 2019-03-22
Openid Connect MEDIUM 6.1
CVE-2019-9837

Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri fi…

Fix: 1.5.4+
Fix from $1,600 2019-03-21
Documentum Webtop MEDIUM 6.1
CVE-2019-7416

XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnera…

No fix yet
Fix from $1,600 2019-03-21
Dotcms MEDIUM 6.1
CVE-2018-17422

dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp…

Fix: 5.0.2+
Fix from $1,600 2019-03-07
Spring Security Oauth MEDIUM 6.5
CVE-2019-3778EPSS 15%

Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported ve…

Fix: 2.0.17 / 2.1.4+
Fix from $1,600 2019-03-07
Excel Viewer MEDIUM 5.5
CVE-2019-0540EPSS 13%

A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file,…

Patch available
Fix from $1,600 2019-03-05
Infosphere Information Governance Catalog MEDIUM 6.1
CVE-2018-1875

IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect …

Mitigation only
Fix from $1,600 2019-03-05
Cloud Private MEDIUM 6.1
CVE-2018-1939

IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a s…

Mitigation only
Fix from $1,600 2019-03-05
Avi Vantage MEDIUM 6.1
CVE-2018-19106

Avi Vantage before 17.2.13 uses an invalid URL encoding during a redirect operation, aka AV-33959.

Fix: 17.2.13+
Fix from $1,600 2019-02-20
Debian Linux MEDIUM 6.1
CVE-2016-10742

Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the req…

Fix: after 3.4.3
Fix from $1,600 2019-02-17
Openam MEDIUM 6.1
CVE-2019-5915

Open redirect vulnerability in OpenAM (Open Source Edition) 13.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishin…

Fix: after 13.0.0-137
Fix from $1,600 2019-02-13
Labkey Server MEDIUM 6.1
CVE-2019-3912

An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticate…

Fix: 18.3.0-61806.763+
Fix from $1,600 2019-01-30
Wise Chat MEDIUM 6.1
CVE-2019-6780

The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and…

Fix: 2.7+
Fix from $1,600 2019-01-24
Ec Cube MEDIUM 6.1
CVE-2018-16191

Open redirect vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3.0.4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-C…

Fix: after 3.0.16
Fix from $1,600 2019-01-09
Learnpress MEDIUM 6.1
CVE-2018-16174

Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishin…

Fix: 3.1.0+
Fix from $1,600 2019-01-09
Ds 570w Firmware MEDIUM 6.1
CVE-2018-0688

Open redirect vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware version…

Fix: 2017-06-12 / 2017-06-19+
Fix from $1,600 2019-01-09
Concourse MEDIUM 5.4
CVE-2018-15798

Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could co…

Fix: 4.2.2+
Fix from $1,600 2018-12-19
Symfony MEDIUM 6.1
CVE-2018-19790

An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4…

Fix: 2.7.50 / 2.8.49+
Fix from $1,600 2018-12-18
Ecostruxure Energy Expert MEDIUM 6.1
CVE-2018-7797

A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME)…

Mitigation only
Fix from $1,600 2018-12-17
Modicom M340 Firmware MEDIUM 6.1
CVE-2018-7804

A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where …

Mitigation only
Fix from $1,600 2018-12-17
Simatic Hmi Comfort Panels Firmware HIGH 8.1
CVE-2018-13813

A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15"…

Fix: after 15.0
Fix from $1,950 2018-12-13
Curam Social Program Management MEDIUM 6.1
CVE-2018-1654

IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phishing attacks, using an open re…

Fix: after 7.0.3.0
Fix from $1,600 2018-12-11
Ninja Forms MEDIUM 6.1
CVE-2018-19796

An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-p…

Fix: 3.3.19.1+
Fix from $1,600 2018-12-03
Vsphere Data Protection MEDIUM 6.1
CVE-2018-11067

Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrate…

Patch available
Fix from $1,600 2018-11-26
Access Manager MEDIUM 6.1
CVE-2018-17948

An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.

Fix: 4.4+
Fix from $1,600 2018-11-20
Netweaver MEDIUM 6.1
CVE-2018-2476

Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.

Mitigation only
Fix from $1,600 2018-11-13
Keycloak MEDIUM 6.1
CVE-2018-14658

A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.Red…

Mitigation only
Fix from $1,600 2018-11-13