Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Drupal MEDIUM 6.1
CVE-2015-2749

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduc…

Patch available
Fix from $1,600 2017-09-13
Drupal MEDIUM 6.1
CVE-2015-2750

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to a…

Patch available
Fix from $1,600 2017-09-13
Banner Student MEDIUM 6.1
CVE-2015-5054

Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary …

No fix yet
Fix from $1,600 2017-09-11
Emptoris Sourcing MEDIUM 5.4
CVE-2017-1449

IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim t…

Mitigation only
Fix from $1,600 2017-08-31
Emptoris Sourcing MEDIUM 6.1
CVE-2017-1450

IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim t…

Mitigation only
Fix from $1,600 2017-08-31
Crushftp MEDIUM 6.1
CVE-2017-14038

CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.

Fix: after 7.7.0
Fix from $1,600 2017-08-30
Curam Social Program Management MEDIUM 6.1
CVE-2017-1195

IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. …

Patch available
Fix from $1,600 2017-08-29
Tivoli Access Manager For E Business MEDIUM 6.1
CVE-2017-1489

IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authenticatio…

Mitigation only
Fix from $1,600 2017-08-29
Enterprise Linux HIGH 7.4
CVE-2017-3085

Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redi…

Fix: after 26.0.0.137
Fix from $1,950 2017-08-11
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2016-8949

IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack…

Mitigation only
Fix from $1,600 2017-08-09
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2017-1448

IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack…

Mitigation only
Fix from $1,600 2017-08-09
Xoops MEDIUM 6.1
CVE-2017-12138

XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.

Mitigation only
Fix from $1,600 2017-08-02
Secret Server MEDIUM 5.4
CVE-2017-11725

The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.

Fix: after 10.2.000018
Fix from $1,600 2017-07-29
Metinfo MEDIUM 6.1
CVE-2017-11718

There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.

Fix: after 5.3.17
Fix from $1,600 2017-07-28
Rhapsody Design Manager MEDIUM 5.4
CVE-2017-1287

IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit…

Patch available
Fix from $1,600 2017-07-24
Finecms MEDIUM 6.1
CVE-2017-11586

dayrui FineCms 5.0.9 has URL Redirector Abuse via the url parameter in a sync action, related to controllers/Weixin.php.

Fix: after 5.0.9
Fix from $1,600 2017-07-24
Bigfix Platform MEDIUM 6.1
CVE-2017-1223

IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit…

Mitigation only
Fix from $1,600 2017-07-19
Oauth2 Proxy MEDIUM 6.1
CVE-2017-1000070

The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAu…

Fix: after 2.1
Fix from $1,600 2017-07-17
phpMyAdmin MEDIUM 6.1
CVE-2017-1000013

phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness

Patch available
Fix from $1,600 2017-07-17
Sme Server MEDIUM 6.1
CVE-2017-1000027

Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting i…

Mitigation only
Fix from $1,600 2017-07-17
Emptoris Sourcing MEDIUM 6.1
CVE-2016-8947

IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a …

Mitigation only
Fix from $1,600 2017-07-12
Emptoris Sourcing MEDIUM 5.4
CVE-2016-8953

IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a …

Patch available
Fix from $1,600 2017-07-12
Exchange Server MEDIUM 6.1
CVE-2017-8621

Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnera…

Patch available
Fix from $1,600 2017-07-11
Websphere Commerce MEDIUM 6.1
CVE-2017-1398

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker to conduct phishing attacks, …

Mitigation only
Fix from $1,600 2017-07-10
Download Manager MEDIUM 6.1
CVE-2017-2217

Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites an…

Fix: after 2.9.50
Fix from $1,600 2017-07-07
Rsa Archer Egrc MEDIUM 6.1
CVE-2017-5002

EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an open redirect vulnerability. A remote unprivileged attacker may…

Mitigation only
Fix from $1,600 2017-07-07
Station Firmware MEDIUM 6.1
CVE-2017-6018

An open redirect issue was discovered in B. Braun Medical SpaceCom module, which is integrated into the SpaceStation docking station: SpaceStation wi…

Mitigation only
Fix from $1,600 2017-06-30
Kibana MEDIUM 6.1
CVE-2016-10365

Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that re…

Fix: after 5.0.0
Fix from $1,600 2017-06-16
Kibana MEDIUM 6.1
CVE-2017-8451

With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a li…

Fix: after 5.3.0
Fix from $1,600 2017-06-16
Piwigo MEDIUM 6.1
CVE-2017-9464

An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sit…

Fix: after 2.9.0
Fix from $1,600 2017-06-14