Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Unclassified MEDIUM 5.1
CVE-2026-42350

Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Kargo is vulnerable to open red…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified MEDIUM 5.3
CVE-2026-3318

Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in the login form endpoint, wher…

Mitigation only
Fix from $1,600 2026-05-08
Electerm CRITICAL 9.6
CVE-2026-43941

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink…

Fix: after 3.8.15
Fix from $2,300 2026-05-08
Unclassified MEDIUM 5.1
CVE-2026-42259

Saltcorn is an extensible, open source, no-code database application builder. Prior to versions 1.4.6, 1.5.6, and 1.6.0-beta.5, Saltcorn validates th…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified CRITICAL 9.6
CVE-2026-6795

URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. …

Mitigation only
Fix from $2,300 2026-05-07
Unclassified HIGH 8.2
CVE-2026-41670

Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionCon…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified MEDIUM 5.3
CVE-2026-40332

Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application incorrectly interprets paths…

No fix yet
Fix from $1,600 2026-05-06
Openclaw HIGH 7.7
CVE-2026-43576

OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pi…

Fix: 2026.4.5+
Fix from $1,950 2026-05-06
Jupyter Server MEDIUM 6.1
CVE-2025-61669

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is …

Fix: 2.18.0+
Fix from $1,600 2026-05-05
N8n MEDIUM 6.1
CVE-2026-42230

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth c…

Fix: 1.123.32 / 2.17.4+
Fix from $1,600 2026-05-04
365 Copilot CRITICAL 9.3
CVE-2026-33102

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Unclassified HIGH 8.1
CVE-2026-40905

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, a password reset poisoning vulnerability was identified in the application…

Mitigation only
Fix from $1,950 2026-04-21
Weblogic Server MEDIUM 6.5
CVE-2026-34315

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are …

Mitigation only
Fix from $1,600 2026-04-21
Identity Manager MEDIUM 6.1
CVE-2026-34283

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected…

Mitigation only
Fix from $1,600 2026-04-21
Business Process Management Suite MEDIUM 6.1
CVE-2026-34284

Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versio…

Mitigation only
Fix from $1,600 2026-04-21
Unclassified MEDIUM 6.9
CVE-2026-40299

next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-need…

Patch available
Fix from $1,600 2026-04-17
HTTP Server MEDIUM 6.1
CVE-2026-40255

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-ne…

Fix: 7.8.1+
Fix from $1,600 2026-04-16
Immich MEDIUM 5.4
CVE-2026-40096

immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the s…

Fix: 2.7.3+
Fix from $1,600 2026-04-15
Netweaver Application Server Abap MEDIUM 6.1
CVE-2026-34257

Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if access…

Mitigation only
Fix from $1,600 2026-04-14
Unclassified MEDIUM 6.1
CVE-2026-6203

The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insuffic…

Mitigation only
Fix from $1,600 2026-04-13
Unclassified MEDIUM 5.3
CVE-2026-39940

ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCRM application to create a lin…

Mitigation only
Fix from $1,600 2026-04-13
Chamilo Lms MEDIUM 6.1
CVE-2026-32932

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows a…

Fix: 1.11.38+
Fix from $1,600 2026-04-10
Rocket.chat MEDIUM 5.3
CVE-2026-22560

An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters with…

Fix: 8.4.0+
Fix from $1,600 2026-04-10
Tomcat MEDIUM 6.1
CVE-2026-25854

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects …

Fix: 9.0.116 / 10.1.53+
Fix from $1,600 2026-04-09
Loris MEDIUM 6.1
CVE-2026-39985

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …

Fix: 27.0.3+
Fix from $1,600 2026-04-09
Openclaw MEDIUM 6.5
CVE-2026-40037

OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies …

Fix: 2026.4.8+
Fix from $1,600 2026-04-08
Aruba Networking Private 5g Core CRITICAL 9.6
CVE-2026-23818

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacke…

Fix: 1.25.3.1+
Fix from $2,300 2026-04-07
Wegia MEDIUM 6.1
CVE-2026-35473

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …

Fix: 3.6.9+
Fix from $1,600 2026-04-06
Wegia MEDIUM 6.1
CVE-2026-35474

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The redirect parameter is taken dir…

Fix: 3.6.9+
Fix from $1,600 2026-04-06
Wegia MEDIUM 6.1
CVE-2026-35475

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET with no URL validation or whi…

Fix: 3.6.9+
Fix from $1,600 2026-04-06