Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Experience Manager MEDIUM 6.1
CVE-2026-47991

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redirect) vulnerability that could …

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.3
CVE-2026-47347

Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it h…

Patch available
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 6.1
CVE-2026-41844

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to…

Fix: 5.3.49 / 6.1.28+
Fix from $1,600 2026-06-09
Digital Experience Compose MEDIUM 6.1
CVE-2026-21826

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header …

Mitigation only
Fix from $1,600 2026-06-05
Misp MEDIUM 6.1
CVE-2026-10861

An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key…

Fix: 2.5.39+
Fix from $1,600 2026-06-04
Misp MEDIUM 6.1
CVE-2026-10856

A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpret…

Fix: 2.5.39+
Fix from $1,600 2026-06-04
Authentik MEDIUM 6.1
CVE-2026-41569

authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter usi…

Fix: 2026.2.3+
Fix from $1,600 2026-06-02
React Router MEDIUM 6.1
CVE-2026-40181

React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigg…

Fix: 6.30.4 / 7.14.1+
Fix from $1,600 2026-06-02
User Oidc MEDIUM 6.1
CVE-2026-45278

Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redire…

Fix: 8.2.2+
Fix from $1,600 2026-06-01
Airflow HIGH 7.2
CVE-2026-40961

A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirec…

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Teamcity MEDIUM 6.1
CVE-2026-49380

In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

Fix: 2026.1+
Fix from $1,600 2026-05-29
Unclassified MEDIUM 6.1
CVE-2026-45307

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to…

Mitigation only
Fix from $1,600 2026-05-28
Authlib MEDIUM 6.1
CVE-2026-44681

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's O…

Fix: 1.6.12+
Fix from $1,600 2026-05-27
Unclassified MEDIUM 5.4
CVE-2026-45335

WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …

Mitigation only
Fix from $1,600 2026-05-27
Snipe It HIGH 7.1
CVE-2026-44833

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to m…

Fix: 8.4.1+
Fix from $1,950 2026-05-26
Shiro MEDIUM 5.4
CVE-2026-48589

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficie…

Fix: 2.2.1+
Fix from $1,600 2026-05-25
Shiro MEDIUM 5.4
CVE-2026-44598

With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. …

Fix: 2.1.1+
Fix from $1,600 2026-05-25
Hackney MEDIUM 6.1
CVE-2026-47070

Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect handler in src/hackney_h3.erl p…

Fix: 4.0.1+
Fix from $1,600 2026-05-25
Devise MEDIUM 6.1
CVE-2026-40295

Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the Fa…

Fix: 5.0.4+
Fix from $1,600 2026-05-22
Devolutions Server MEDIUM 5.0
CVE-2026-9245

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect vi…

Fix: 2025.3.22.0 / 2026.1.19.0+
Fix from $1,600 2026-05-22
Powerflex Appliance Intelligent Catalog HIGH 8.2
CVE-2025-26483

Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this…

Fix: 3.7.8.0 / 48.383.00+
Fix from $1,950 2026-05-22
Build Of Keycloak HIGH 8.1
CVE-2026-7504

A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation …

Fix: 26.4.12+
Fix from $1,950 2026-05-19
Simplesamlphp Module Casserver MEDIUM 6.1
CVE-2025-65954

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logou…

Fix: 6.3.1+
Fix from $1,600 2026-05-18
Tabby HIGH 7.1
CVE-2026-45037

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly t…

Fix: 1.0.232+
Fix from $1,950 2026-05-15
Unclassified MEDIUM 6.1
CVE-2026-42207

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified MEDIUM 5.7
CVE-2026-44520

Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to …

Mitigation only
Fix from $1,600 2026-05-14
Unclassified HIGH 7.0
CVE-2026-44503

The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to st…

Mitigation only
Fix from $1,950 2026-05-14
Angular Cli MEDIUM 6.1
CVE-2026-44437

The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a…

Fix: 19.2.25 / 20.3.25+
Fix from $1,600 2026-05-13
Unclassified HIGH 8.1
CVE-2026-45055

CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at boots…

Mitigation only
Fix from $1,950 2026-05-13
Nitro MEDIUM 6.1
CVE-2026-44372

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cros…

Fix: 2.13.4 / 3.0.260429+
Fix from $1,600 2026-05-13