Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Twake MEDIUM 6.1
CVE-2025-70037

An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sen…

Mitigation only
Fix from $1,600 2026-03-09
Zitadel CRITICAL 9.3
CVE-2026-29067

ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password rese…

Fix: 4.7.1+
Fix from $2,300 2026-03-07
Internet Routing Registry Daemon HIGH 8.1
CVE-2026-28681

Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version…

Fix: 4.4.5 / 4.5.1+
Fix from $1,950 2026-03-06
Isurlinportal MEDIUM 6.1
CVE-2026-28413

Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil…

Fix: 2.1.0 / 3.1.0+
Fix from $1,600 2026-03-05
Allauth MEDIUM 6.1
CVE-2026-27982

An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default),…

Fix: 65.14.1+
Fix from $1,600 2026-03-05
Affine MEDIUM 6.1
CVE-2026-25477

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at t…

Fix: 0.26.0+
Fix from $1,600 2026-03-02
Bigbluebutton MEDIUM 6.1
CVE-2026-27736

BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks val…

Fix: 3.0.20+
Fix from $1,600 2026-02-25
Unclassified MEDIUM 6.9
CVE-2026-27738

The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic …

Patch available
Fix from $1,600 2026-02-25
Teamcity MEDIUM 6.1
CVE-2026-28194

In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

Fix: 2025.11.3+
Fix from $1,600 2026-02-25
Openemr MEDIUM 6.1
CVE-2026-24847

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form mo…

Fix: 8.0.0+
Fix from $1,600 2026-02-25
Horilla MEDIUM 6.1
CVE-2026-3049

A vulnerability was detected in horilla-opensource horilla up to 1.0.2. This issue affects the function get of the file horilla_generics/global_searc…

Fix: 1.0.3+
Fix from $1,600 2026-02-24
Traccar HIGH 8.7
CVE-2026-25649

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 …

Fix: after 6.11.1
Fix from $1,950 2026-02-23
Feathers MEDIUM 6.1
CVE-2026-27191

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.39 and below the redirect quer…

Fix: 5.0.40+
Fix from $1,600 2026-02-21
Spip MEDIUM 6.1
CVE-2025-71244

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visit…

Fix: 4.3.9 / 4.4.5+
Fix from $1,600 2026-02-19
Enterprise Server CRITICAL 9.0
CVE-2026-0573

An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorizatio…

Fix: 3.14.22 / 3.15.17+
Fix from $2,300 2026-02-18
Unclassified MEDIUM 6.1
CVE-2026-1296

The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to i…

Mitigation only
Fix from $1,600 2026-02-18
Db2 Recovery Expert MEDIUM 6.1
CVE-2025-27900

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By pers…

Patch available
Fix from $1,600 2026-02-17
Fastgpt MEDIUM 5.4
CVE-2026-26003

FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through FastGPT/api/plugin/xxx witho…

Fix: 4.14.5+
Fix from $1,600 2026-02-10
Frappe MEDIUM 6.1
CVE-2026-25956

Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site whi…

Fix: 14.99.14 / 15.94.0+
Fix from $1,600 2026-02-10
Business Server Pages MEDIUM 6.1
CVE-2026-24328

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect th…

Mitigation only
Fix from $1,600 2026-02-10
Document Management System MEDIUM 6.1
CVE-2026-24323

The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sa…

Mitigation only
Fix from $1,600 2026-02-10
Businessobjects Business Intelligence Platform HIGH 8.1
CVE-2026-0508

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the appli…

Mitigation only
Fix from $1,950 2026-02-10
Sap Basis MEDIUM 6.5
CVE-2026-0484

Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa…

Mitigation only
Fix from $1,600 2026-02-10
Fast\/tools MEDIUM 6.1
CVE-2025-66596

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate request headers. W…

Mitigation only
Fix from $1,600 2026-02-09
Doorman MEDIUM 6.1
CVE-2026-2153

A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. E…

Fix: after 0.6
Fix from $1,600 2026-02-08
Client Certificate Auth MEDIUM 6.1
CVE-2026-25651

client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of clien…

Fix: 1.0.0+
Fix from $1,600 2026-02-06
Br 6258n Firmware MEDIUM 6.1
CVE-2026-1970

A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipu…

Fix: after 1.18
Fix from $1,600 2026-02-05
Evolved Programmable Network Manager MEDIUM 6.1
CVE-2026-20123

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow…

Fix: 3.10.6 / 8.1.1+
Fix from $1,600 2026-02-04
Qwik MEDIUM 6.1
CVE-2026-25149

Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler mi…

Fix: 1.19.0+
Fix from $1,600 2026-02-03
Claude Code HIGH 7.4
CVE-2026-24052

Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification…

Fix: 1.0.111+
Fix from $1,950 2026-02-03