Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Jira MEDIUM 6.1
CVE-2018-13401

The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5…

Fix: 7.6.9 / 7.7.5+
Fix from $1,600 2018-10-23
Jira MEDIUM 6.1
CVE-2018-13402

Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version…

Fix: 7.6.9 / 7.7.5+
Fix from $1,600 2018-10-23
H.264 Poe Ip Camera Firmware MEDIUM 6.1
CVE-2018-12675

The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camer…

No fix yet
Fix from $1,600 2018-10-19
Vbulletin MEDIUM 6.1
CVE-2018-15493

vBulletin 5.4.3 has an Open Redirect.

Patch available
Fix from $1,600 2018-10-17
Unified Communications Manager MEDIUM 5.4
CVE-2018-15403

A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Pr…

Mitigation only
Fix from $1,600 2018-10-05
Xbtit MEDIUM 6.1
CVE-2018-17870

An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnera…

Patch available
Fix from $1,600 2018-10-01
Emc Unity Firmware HIGH 8.1
CVE-2018-1251

Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could pote…

Fix: 4.3.1.1525703027+
Fix from $1,950 2018-09-28
Platform Symphony MEDIUM 5.4
CVE-2018-1704

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks,…

Mitigation only
Fix from $1,600 2018-09-28
Websphere Portal MEDIUM 6.1
CVE-2018-1736

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a…

Patch available
Fix from $1,600 2018-09-27
Webcenter Interaction MEDIUM 6.1
CVE-2018-16954

An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also c…

Patch available
Fix from $1,600 2018-09-18
Feed Statistics MEDIUM 6.1
CVE-2018-17074

The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.

Fix: 4.0+
Fix from $1,600 2018-09-16
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2018-5548

On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured w…

Fix: after 11.6.3
Fix from $1,600 2018-09-13
Eventum MEDIUM 6.1
CVE-2018-16761

Eventum before 3.4.0 has an open redirect vulnerability.

Fix: 3.4.0+
Fix from $1,600 2018-09-09
Cremecrm MEDIUM 6.1
CVE-2018-14398

An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a…

No fix yet
Fix from $1,600 2018-09-07
Connect Secure MEDIUM 6.1
CVE-2018-14366

download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and …

Mitigation only
Fix from $1,600 2018-09-06
Debian Linux MEDIUM 6.1
CVE-2018-1000671

sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of th…

No fix yet
Fix from $1,600 2018-09-06
Xbtit MEDIUM 6.1
CVE-2018-15683

An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. I…

Fix: after 2.5.4
Fix from $1,600 2018-09-05
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-15419

Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by …

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Url Parse CRITICAL 10.0
CVE-2018-3774

Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authenticati…

Fix: 1.4.3+
Fix from $2,300 2018-08-12
Edirectory MEDIUM 6.1
CVE-2018-7692

Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.

Fix: after 9.1.1
Fix from $1,600 2018-08-09
Gogs MEDIUM 6.1
CVE-2018-15178

Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an i…

Fix: 0.12+
Fix from $1,600 2018-08-08
Xp 9000 Command View MEDIUM 6.1
CVE-2018-7091

HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of Dev…

Fix: 8.60-00+
Fix from $1,600 2018-08-06
Icewall Sso CRITICAL 9.1
CVE-2017-8989

A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.

Mitigation only
Fix from $2,300 2018-08-06
Django MEDIUM 6.1
CVE-2018-14574EPSS 25%

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

Fix: 1.11.15 / 2.0.8+
Fix from $1,600 2018-08-03
Orange Forum MEDIUM 6.1
CVE-2018-14474

views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.

Patch available
Fix from $1,600 2018-07-20
Pagekit MEDIUM 6.1
CVE-2018-14381

Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.

Fix: 1.0.14+
Fix from $1,600 2018-07-18
Inotes MEDIUM 6.1
CVE-2013-0594

Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sit…

Patch available
Fix from $1,600 2018-07-11
Fortianalyzer MEDIUM 6.1
CVE-2018-1355

An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacke…

Fix: after 5.6.5
Fix from $1,600 2018-06-27
Redirection HIGH 7.2
CVE-2018-1000504

Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows admins to execute any PHP fi…

No fix yet
Fix from $1,950 2018-06-26
Cloud Foundry Uaa MEDIUM 6.1
CVE-2018-11041

Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 exc…

Fix: 4.7.5 / 4.10.1+
Fix from $1,600 2018-06-25