Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Symfony MEDIUM 6.1
CVE-2018-11408

The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and…

Fix: 2.7.48 / 2.8.41+
Fix from $1,600 2018-06-13
Symfony MEDIUM 6.1
CVE-2017-16652

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSucce…

Fix: 2.7.38 / 2.8.31+
Fix from $1,600 2018-06-13
Firefox MEDIUM 6.1
CVE-2017-5389

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests…

Fix: 51.0+
Fix from $1,600 2018-06-11
Firefox HIGH 8.8
CVE-2016-9078

Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in…

Patch available
Fix from $1,950 2018-06-11
St MEDIUM 6.1
CVE-2017-16224

st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domai…

Fix: after 1.2.1
Fix from $1,600 2018-06-07
Connections MEDIUM 6.1
CVE-2017-1748

IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to…

Patch available
Fix from $1,600 2018-06-04
Hekto MEDIUM 6.1
CVE-2018-3743

Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.

Fix: after 0.2.3
Fix from $1,600 2018-06-01
Xenmobile Server MEDIUM 6.1
CVE-2018-10651

There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

Mitigation only
Fix from $1,600 2018-05-23
Hue MEDIUM 6.1
CVE-2015-8094

Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac…

Fix: 3.10.0+
Fix from $1,600 2018-05-22
Ilias MEDIUM 6.1
CVE-2018-11119

ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.

Fix: after 5.3.4
Fix from $1,600 2018-05-17
Mybb MEDIUM 6.1
CVE-2018-10678

MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers…

Mitigation only
Fix from $1,600 2018-05-13
Google Login MEDIUM 6.1
CVE-2018-1000174

An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirec…

Fix: after 1.3
Fix from $1,600 2018-05-08
Authentication Manager MEDIUM 6.1
CVE-2018-1248

RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header inject…

Fix: after 8.3
Fix from $1,600 2018-05-08
Blackboard Learn MEDIUM 6.1
CVE-2017-18262

Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shi…

Fix: after 9.1
Fix from $1,600 2018-04-30
WordPress MEDIUM 6.1
CVE-2018-10100

Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.

Fix: 4.9.5+
Fix from $1,600 2018-04-16
WordPress MEDIUM 6.1
CVE-2018-10101

Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.

Fix: 4.9.5+
Fix from $1,600 2018-04-16
Debian Linux MEDIUM 6.1
CVE-2017-0363

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux MEDIUM 6.1
CVE-2017-0364

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Safari MEDIUM 6.1
CVE-2017-7153

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is aff…

Fix: 4.2 / 7.2+
Fix from $1,600 2018-04-03
Kibana MEDIUM 6.1
CVE-2018-3819

The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerab…

Fix: 5.6.7 / 6.1.3+
Fix from $1,600 2018-03-30
Identity Manager MEDIUM 6.1
CVE-2018-7674

The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.

Fix: after 4.6
Fix from $1,600 2018-03-28
Open Audit MEDIUM 6.1
CVE-2018-8937

An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI …

No fix yet
Fix from $1,600 2018-03-26
Exchange Server MEDIUM 6.5
CVE-2018-0924EPSS 8%

Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 C…

Patch available
Fix from $1,600 2018-03-14
Rsa Archer MEDIUM 6.1
CVE-2018-1220

EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit thi…

Fix: 6.2.0.8+
Fix from $1,600 2018-03-08
Sowifi Hotspot Firmware MEDIUM 6.1
CVE-2018-7473

Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attackers to redirect users to arbit…

Mitigation only
Fix from $1,600 2018-03-07
Access Manager MEDIUM 6.1
CVE-2017-14802

Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects t…

Fix: after 4.3
Fix from $1,600 2018-03-02
Bonita Bpm Portal MEDIUM 6.1
CVE-2015-3898EPSS 6%

Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct …

Fix: 6.5.3+
Fix from $1,600 2018-02-28
Radar MEDIUM 6.1
CVE-2018-6324

F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login.

Fix: after 3.9.1
Fix from $1,600 2018-02-16
Icewall Federation Agent MEDIUM 6.1
CVE-2017-8945

A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.

Mitigation only
Fix from $1,600 2018-02-15
Sitefinity MEDIUM 6.1
CVE-2017-18178

Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the tar…

No fix yet
Fix from $1,600 2018-02-12