Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Unified Communications Domain Manager MEDIUM 6.1
CVE-2017-6670

A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a use…

Mitigation only
Fix from $1,600 2017-06-13
Sleipnir MEDIUM 6.1
CVE-2016-7831

Sleipnir 4 Black Edition for Mac 4.5.3 and earlier and Sleipnir 4 for Mac 4.5.3 and earlier (Mac App Store) may allow a remote attacker to spoof the …

Fix: after 4.5.3
Fix from $1,600 2017-06-09
Device Manager MEDIUM 6.1
CVE-2017-9296

Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows remote attackers to redirect …

Fix: after 8.5.2
Fix from $1,600 2017-05-29
Device Manager MEDIUM 6.1
CVE-2017-9297

Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to redirect users to arbitrary web sites.

Fix: after 8.5.2
Fix from $1,600 2017-05-29
Fortiportal MEDIUM 6.1
CVE-2017-7343

An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter.

Fix: after 4.0.0
Fix from $1,600 2017-05-27
Fortianalyzer Firmware MEDIUM 6.1
CVE-2017-3126

An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthor…

Mitigation only
Fix from $1,600 2017-05-27
Cf Release MEDIUM 6.1
CVE-2015-3190

With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or e…

Fix: after 209
Fix from $1,600 2017-05-25
Business Process Manager MEDIUM 5.4
CVE-2017-1159

IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vi…

Patch available
Fix from $1,600 2017-05-22
Iphone Os MEDIUM 6.1
CVE-2017-2497

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "iBooks" c…

Fix: after 10.12.4
Fix from $1,600 2017-05-22
Juddi MEDIUM 6.1
CVE-2015-5241

After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect…

Mitigation only
Fix from $1,600 2017-05-19
WordPress HIGH 8.6
CVE-2017-9062

In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.

Fix: after 4.7.4
Fix from $1,950 2017-05-18
Wow Moodboard Lite MEDIUM 6.1
CVE-2015-4070

Open redirect vulnerability in the proxyimages function in wowproxy.php in the Wow Moodboard Lite plugin 1.1.1.1 for WordPress allows remote attacker…

Mitigation only
Fix from $1,600 2017-05-17
Splunk MEDIUM 6.1
CVE-2016-4857

Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.1…

Fix: after 6.4.2
Fix from $1,600 2017-05-12
Splunk MEDIUM 6.1
CVE-2016-4859

Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.1…

Fix: after 6.4.2
Fix from $1,600 2017-05-12
Advanced Secure Gateway MEDIUM 6.1
CVE-2016-9099

Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 ar…

Fix: 6.5.10.6 / 6.7.2.1+
Fix from $1,600 2017-05-11
Websphere Portal HIGH 8.8
CVE-2017-1156

IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to …

Patch available
Fix from $1,950 2017-05-05
Proxmox Mail Gateway MEDIUM 6.1
CVE-2015-9058

Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites a…

Fix: after 4.0-4
Fix from $1,600 2017-05-03
Opsview MEDIUM 6.1
CVE-2016-10368

Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a cer…

No fix yet
Fix from $1,600 2017-05-03
Applications Framework MEDIUM 5.4
CVE-2017-3528EPSS 15%

Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, et…

Patch available
Fix from $1,600 2017-04-24
Opera Browser MEDIUM 6.1
CVE-2016-4075

Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.

No fix yet
Fix from $1,600 2017-04-21
Garoon MEDIUM 6.1
CVE-2016-1213

The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites.

Fix: after 4.2.1
Fix from $1,600 2017-04-20
Marketing Platform MEDIUM 5.4
CVE-2016-0228

IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts. A…

Patch available
Fix from $1,600 2017-04-17
Jive MEDIUM 6.1
CVE-2016-4334

Jive before 2016.3.1 has an open redirect from the external-link.jspa page.

Fix: after 2016.3
Fix from $1,600 2017-04-10
Registered Envelope Service MEDIUM 6.1
CVE-2017-3889

A vulnerability in the web interface of the Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to redirect a user to a…

Mitigation only
Fix from $1,600 2017-04-07
Unified Computing System MEDIUM 6.1
CVE-2017-6604

A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redi…

Mitigation only
Fix from $1,600 2017-04-07
Django MEDIUM 6.1
CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. T…

Mitigation only
Fix from $1,600 2017-04-04
Django MEDIUM 6.1
CVE-2017-7234

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` v…

Mitigation only
Fix from $1,600 2017-04-04
Al3g Firmware MEDIUM 6.1
CVE-2016-10315

Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.0…

No fix yet
Fix from $1,600 2017-04-03
Al3g Firmware MEDIUM 6.1
CVE-2016-10316

Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.0…

No fix yet
Fix from $1,600 2017-04-03
Security Monkey MEDIUM 6.1
CVE-2017-7266

Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain …

Fix: after 0.7.0
Fix from $1,600 2017-03-26