Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Emptoris Sourcing MEDIUM 5.4
CVE-2016-0329

Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, …

Fix: after 10.1.0.0
Fix from $1,600 2018-02-02
Simplesamlphp MEDIUM 6.1
CVE-2018-6520

SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.

Fix: 1.15.1+
Fix from $1,600 2018-02-02
Groupsession MEDIUM 6.1
CVE-2017-2166

Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishin…

Fix: after 4.7.0
Fix from $1,600 2018-01-26
Vbulletin MEDIUM 6.1
CVE-2018-6200

vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter.

Fix: after 4.2.5
Fix from $1,600 2018-01-25
Prime Infrastructure MEDIUM 6.1
CVE-2018-0097

A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious …

Mitigation only
Fix from $1,600 2018-01-18
Security Access Manager For Web Firmware MEDIUM 6.1
CVE-2017-1534

IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By pe…

Mitigation only
Fix from $1,600 2018-01-10
Security Key Lifecycle Manager MEDIUM 6.1
CVE-2017-1668

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persu…

Mitigation only
Fix from $1,600 2018-01-09
Plone MEDIUM 6.1
CVE-2017-1000484

By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the …

Mitigation only
Fix from $1,600 2018-01-03
Plone MEDIUM 6.1
CVE-2017-1000481

When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. Aft…

Mitigation only
Fix from $1,600 2018-01-03
Furikake MEDIUM 6.1
CVE-2017-1000434

Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allows for a redirect to an attac…

No fix yet
Fix from $1,600 2018-01-02
Maximo Asset Management MEDIUM 6.1
CVE-2017-1558

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vic…

Mitigation only
Fix from $1,600 2017-12-13
Sap Kernel MEDIUM 6.1
CVE-2017-16679

URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21…

Mitigation only
Fix from $1,600 2017-12-12
Kibana MEDIUM 6.1
CVE-2017-11482

The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vuln…

Mitigation only
Fix from $1,600 2017-12-08
Robohelp MEDIUM 6.1
CVE-2017-3105

Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.

Fix: 12.0.4.460 / 2017.0.1+
Fix from $1,600 2017-12-01
Data Center Network Manager MEDIUM 6.1
CVE-2017-12344

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM conf…

Mitigation only
Fix from $1,600 2017-11-30
Phoenix MEDIUM 6.1
CVE-2017-1000163

The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, w…

Mitigation only
Fix from $1,600 2017-11-17
Asp.net Core HIGH 8.8
CVE-2017-11879EPSS 9%

ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP…

Patch available
Fix from $1,950 2017-11-15
Buildmaster MEDIUM 6.1
CVE-2017-16761

An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.

Fix: 5.8.2+
Fix from $1,600 2017-11-10
Arcsight Enterprise Security Manager MEDIUM 6.1
CVE-2017-14358

A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.…

Mitigation only
Fix from $1,600 2017-10-31
Web2py MEDIUM 6.1
CVE-2015-6961

Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct phishing …

Patch available
Fix from $1,600 2017-10-18
Drupal MEDIUM 6.1
CVE-2015-7943

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABj…

Mitigation only
Fix from $1,600 2017-10-18
Git HIGH 8.8
CVE-2017-1000117EPSS 78%

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that …

Fix: after 2.7.5
Fix from $1,950 2017-10-05
Cf Release MEDIUM 6.1
CVE-2017-8047

In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possibl…

Fix: after 273
Fix from $1,600 2017-10-04
Documentum Administrator MEDIUM 6.1
CVE-2017-14524

Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web s…

Mitigation only
Fix from $1,600 2017-09-28
Documentum Administrator MEDIUM 6.1
CVE-2017-14525

Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites an…

Mitigation only
Fix from $1,600 2017-09-28
Xsuite MEDIUM 6.1
CVE-2015-4668EPSS 7%

Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac…

No fix yet
Fix from $1,600 2017-09-25
WordPress MEDIUM 5.4
CVE-2017-14725

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

Fix: after 4.8.1
Fix from $1,600 2017-09-23
Joomla\! MEDIUM 6.1
CVE-2015-5608

Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.

Mitigation only
Fix from $1,600 2017-09-20
Phpbb MEDIUM 6.1
CVE-2015-3880

Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web…

Fix: after 3.0.14
Fix from $1,600 2017-09-19
Python Fedora MEDIUM 6.1
CVE-2017-1002150

python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection

Fix: after 0.8.0
Fix from $1,600 2017-09-14