Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Plone MEDIUM 6.1
CVE-2016-7137

Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect…

Patch available
Fix from $1,600 2017-03-07
Flexnet Publisher MEDIUM 6.1
CVE-2017-5571

Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix L…

Fix: after 11.14.1
Fix from $1,600 2017-03-03
Cpanel MEDIUM 6.1
CVE-2017-5614

Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via…

Fix: 11.54.0.36 / 56.0.43+
Fix from $1,600 2017-03-03
Cgiecho MEDIUM 6.1
CVE-2017-5615

cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.

Mitigation only
Fix from $1,600 2017-03-03
Secure Access Control System MEDIUM 6.1
CVE-2017-3840

A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to redirect a us…

Mitigation only
Fix from $1,600 2017-02-22
Webdatorcentral MEDIUM 6.1
CVE-2016-8376

An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0. This non-validated redirect/non-validated forward (OPE…

Mitigation only
Fix from $1,600 2017-02-13
Prime Service Catalog MEDIUM 5.4
CVE-2017-3810

A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attac…

Mitigation only
Fix from $1,600 2017-02-03
License Metric Tool MEDIUM 6.1
CVE-2016-8961

IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a s…

Fix: after 9.2
Fix from $1,600 2017-02-01
Sterling B2b Integrator MEDIUM 6.1
CVE-2016-6020

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading …

Patch available
Fix from $1,600 2017-02-01
Opera Browser MEDIUM 6.1
CVE-2016-6908

Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to misha…

Mitigation only
Fix from $1,600 2017-01-26
Webex Meeting Center MEDIUM 5.4
CVE-2017-3799

A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection. More In…

Mitigation only
Fix from $1,600 2017-01-26
Serendipity MEDIUM 6.1
CVE-2017-5474

Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct …

Fix: after 2.0.5
Fix from $1,600 2017-01-14
Puppet Enterprise MEDIUM 6.1
CVE-2015-6501

Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and …

Fix: after 2015.2.0
Fix from $1,600 2017-01-12
Puppet Enterprise MEDIUM 6.1
CVE-2016-5715

Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitr…

Fix: after 2016.4.0
Fix from $1,600 2017-01-12
Cloud Foundry Ops Manager HIGH 7.4
CVE-2016-6657

An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply …

Mitigation only
Fix from $1,950 2016-12-16
Open Xchange Appsuite HIGH 7.4
CVE-2016-3174

An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The "defer" servlet offers to redirect a client to a specified URL. Since som…

Fix: after 7.8.0
Fix from $1,950 2016-12-15
Filenet Workplace MEDIUM 6.8
CVE-2016-3047

Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to redirect users to arbitrary we…

Mitigation only
Fix from $1,600 2016-12-01
Drupal MEDIUM 6.8
CVE-2016-9451

Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.

Patch available
Fix from $1,600 2016-11-25
Cloud Orchestrator MEDIUM 6.8
CVE-2016-0204

Open redirect vulnerability in IBM Cloud Orchestrator 2.4.x before 2.4.0 FP3 allows remote authenticated users to redirect users to arbitrary web sit…

Patch available
Fix from $1,600 2016-10-16
Flask Oidc HIGH 7.4
CVE-2016-1000001

flask-oidc version 0.1.2 and earlier is vulnerable to an open redirect

Fix: after 0.1.2
Fix from $1,950 2016-10-07
Cloud Foundry Uaa Bosh MEDIUM 5.3
CVE-2016-6636

The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4;…

Fix: after 241
Fix from $1,600 2016-09-30
Tealeaf Customer Experience MEDIUM 6.8
CVE-2016-5977

Open redirect vulnerability in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 b…

Fix: after 8.7
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance MEDIUM 6.8
CVE-2016-3040

IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, a…

Patch available
Fix from $1,600 2016-09-26
Cloud Foundry Elastic Runtime HIGH 7.4
CVE-2016-0928

Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to …

Fix: after 1.6.29
Fix from $1,950 2016-09-18
Filenet Workplace MEDIUM 6.8
CVE-2016-5878

Open redirect vulnerability in IBM FileNet Workplace 4.0.2 before 4.0.2.14 allows remote authenticated users to redirect users to arbitrary web sites…

Patch available
Fix from $1,600 2016-08-08
Safari MEDIUM 5.4
CVE-2016-4604

Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP por…

Mitigation only
Fix from $1,600 2016-07-22
Linux HIGH 8.1
CVE-2016-5385EPSS 50%

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presen…

Fix: 5.5.38 / 5.6.24+
Fix from $1,950 2016-07-19
Novius Os MEDIUM 5.8
CVE-2015-5354EPSS 13%

Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks …

No fix yet
Fix from $1,600 2015-07-01
Telepresence Tc Software MEDIUM 5.8
CVE-2015-0697

Open redirect vulnerability in the login page in Cisco TC Software before 6.3-26 and 7.x before 7.3.0 on Cisco TelePresence Collaboration Desk and Ro…

Mitigation only
Fix from $1,600 2015-04-15
Network Satellite MEDIUM 6.5
CVE-2011-1594

A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to ar…

Patch available
Fix from $1,600 2014-02-05