Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Directus MEDIUM 6.1
CVE-2026-35410

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login…

Fix: 11.16.1+
Fix from $1,600 2026-04-06
Openedx MEDIUM 6.1
CVE-2026-35404

Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a redirect_url GET parameter t…

Fix: after 2026-04-02
Fix from $1,600 2026-04-06
Wegia MEDIUM 6.1
CVE-2026-35472

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …

Fix: 3.6.9+
Fix from $1,600 2026-04-06
Wegia MEDIUM 6.1
CVE-2026-35396

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …

Fix: 3.6.9+
Fix from $1,600 2026-04-06
Wegia MEDIUM 6.1
CVE-2026-35398

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …

Fix: 3.6.9+
Fix from $1,600 2026-04-06
Signinghub MEDIUM 6.1
CVE-2025-61166

An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL.

No fix yet
Fix from $1,600 2026-04-06
Homarr HIGH 8.8
CVE-2026-33510

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login…

Fix: 1.57.0+
Fix from $1,950 2026-04-06
Unclassified HIGH 7.5
CVE-2018-25245

7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings …

No fix yet
Fix from $1,950 2026-04-04
Jupyterhub MEDIUM 6.1
CVE-2026-33709

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in…

Fix: 5.4.4+
Fix from $1,600 2026-04-03
Casdoor MEDIUM 6.1
CVE-2026-5467

A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request …

Mitigation only
Fix from $1,600 2026-04-03
Hoppscotch MEDIUM 6.1
CVE-2026-34847

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. …

Fix: 2026.3.0+
Fix from $1,600 2026-04-02
Hoppscotch CRITICAL 9.6
CVE-2026-34931

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfilt…

Fix: 2026.3.0+
Fix from $2,300 2026-04-02
Signal K Server MEDIUM 6.1
CVE-2026-34083

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server contains a code-level vulnerabi…

Fix: 2.24.0+
Fix from $1,600 2026-04-02
Build Of Keycloak HIGH 7.3
CVE-2026-3872

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect…

Mitigation only
Fix from $1,950 2026-04-02
Xenforo MEDIUM 6.1
CVE-2024-58342

XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the …

Fix: 2.2.17+
Fix from $1,600 2026-04-01
Freescout MEDIUM 6.1
CVE-2026-34442

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout ve…

Fix: 1.8.211+
Fix from $1,600 2026-03-31
Discourse MEDIUM 6.1
CVE-2026-32113

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Statamic MEDIUM 6.1
CVE-2026-33885

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redir…

Fix: 5.73.16 / 6.7.2+
Fix from $1,600 2026-03-27
Mastodon MEDIUM 6.1
CVE-2026-33868

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redi…

Fix: 4.3.21 / 4.4.15+
Fix from $1,600 2026-03-27
Polis HIGH 8.8
CVE-2026-33506

Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a …

Fix: 26.2.0+
Fix from $1,950 2026-03-26
Angular Cli MEDIUM 6.1
CVE-2026-33397

The Angular SSR is a server-rise rendering tool for Angular applications. Versions on the 22.x branch prior to 22.0.0-next.2, the 21.x branch prior t…

Fix: 20.3.21 / 21.2.3+
Fix from $1,600 2026-03-26
Avideo MEDIUM 6.1
CVE-2026-33296

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a us…

Fix: 26.0+
Fix from $1,600 2026-03-22
Suitecrm MEDIUM 6.1
CVE-2026-29105

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCR…

Fix: 7.15.1 / 8.9.3+
Fix from $1,600 2026-03-19
Account MEDIUM 6.1
CVE-2026-20994

URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.

Fix: 15.5.01.1+
Fix from $1,600 2026-03-16
Quay MEDIUM 5.4
CVE-2026-2376

A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by prov…

Patch available
Fix from $1,600 2026-03-12
Organization Portal System MEDIUM 6.1
CVE-2026-3824

IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visit…

Mitigation only
Fix from $1,600 2026-03-11
Arubaos Cx MEDIUM 6.1
CVE-2026-23817

A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbit…

Fix: 10.10.1180 / 10.13.1161+
Fix from $1,600 2026-03-11
Sylius MEDIUM 6.1
CVE-2026-31819

Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and…

Fix: 1.9.12 / 1.10.16+
Fix from $1,600 2026-03-10
Pocket Id MEDIUM 6.1
CVE-2026-28512

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback …

Fix: 2.4.0+
Fix from $1,600 2026-03-10
Sunbirded Portal MEDIUM 6.1
CVE-2025-70032

An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

Mitigation only
Fix from $1,600 2026-03-09