Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Moodle MEDIUM 6.1
CVE-2025-67852

A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled …

Fix: 4.1.22 / 4.4.11+
Fix from $1,600 2026-02-03
Nocodb MEDIUM 6.1
CVE-2026-24768

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an unvalidated redirect (open redirect) vulnerability exists in …

Fix: 0.301.0+
Fix from $1,600 2026-01-28
Weasyprint HIGH 7.5
CVE-2025-68616

WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in Weas…

Fix: 68.0+
Fix from $1,950 2026-01-19
Wegia MEDIUM 6.1
CVE-2026-23729

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …

Fix: 3.6.2+
Fix from $1,600 2026-01-16
Wegia MEDIUM 6.1
CVE-2026-23730

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …

Fix: 3.6.2+
Fix from $1,600 2026-01-16
Wegia MEDIUM 6.1
CVE-2026-23726

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, An Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …

Fix: 3.6.2+
Fix from $1,600 2026-01-16
Wegia MEDIUM 6.1
CVE-2026-23727

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …

Fix: 3.6.2+
Fix from $1,600 2026-01-16
Wegia MEDIUM 6.1
CVE-2026-23728

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …

Fix: 3.6.2+
Fix from $1,600 2026-01-16
Tdc X401gl Firmware MEDIUM 6.1
CVE-2026-22912

Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various r…

Fix: 1.5.0+
Fix from $1,600 2026-01-15
React Router MEDIUM 6.5
CVE-2025-68470

React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path can be crafted so that when a…

Fix: after 7.9.5
Fix from $1,600 2026-01-10
Directus MEDIUM 6.1
CVE-2026-22032

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in t…

Fix: 11.14.0+
Fix from $1,600 2026-01-08
Curl MEDIUM 5.3
CVE-2025-14524

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, …

Fix: 8.18.0+
Fix from $1,600 2026-01-08
Kanboard MEDIUM 6.1
CVE-2026-21879

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allow…

Fix: 1.2.49+
Fix from $1,600 2026-01-08
Unclassified CRITICAL 9.8
CVE-2019-25282

V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that allows attackers to manipulate the 'parent' GET paramet…

Mitigation only
Fix from $2,300 2026-01-08
Opencti MEDIUM 6.1
CVE-2025-61782

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirect vulnera…

Fix: 6.8.3+
Fix from $1,600 2026-01-07
Unclassified CRITICAL 9.8
CVE-2020-36912

Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manip…

Mitigation only
Fix from $2,300 2026-01-06
Lares Firmware MEDIUM 5.4
CVE-2025-15112

Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipula…

Mitigation only
Fix from $1,600 2025-12-30
Br 6208ac Firmware MEDIUM 6.1
CVE-2025-15258

A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the function formALGSetup of the file /goform/formALGSetup of…

No fix yet
Fix from $1,600 2025-12-30
Unclassified MEDIUM 6.1
CVE-2025-55060

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

No fix yet
Fix from $1,600 2025-12-29
Blitz MEDIUM 6.1
CVE-2025-60935

An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL…

Mitigation only
Fix from $1,600 2025-12-24
Online Food Delivery System MEDIUM 5.4
CVE-2025-1885

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Phishi…

Mitigation only
Fix from $1,600 2025-12-19
Safari CRITICAL 9.8
CVE-2025-43526

This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web…

Fix: 26.2+
Fix from $2,300 2025-12-17
Avideo MEDIUM 6.1
CVE-2025-34439

AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An atta…

Fix: 20.0+
Fix from $1,600 2025-12-17
Avideo MEDIUM 6.1
CVE-2025-34440

AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user r…

Fix: 20.0+
Fix from $1,600 2025-12-17
Mattermost Server MEDIUM 6.1
CVE-2025-62690

Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a maliciou…

Fix: 10.11.5+
Fix from $1,600 2025-12-17
Abp MEDIUM 5.3
CVE-2025-65581

An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUr…

Fix: 10.0.0+
Fix from $1,600 2025-12-16
Wbce Cms MEDIUM 6.1
CVE-2023-53901

WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attac…

No fix yet
Fix from $1,600 2025-12-16
Mayan Edms MEDIUM 6.1
CVE-2025-14692

A flaw has been found in Mayan EDMS up to 4.10.1. The impacted element is an unknown function of the file /authentication/. This manipulation causes …

Fix: 4.10.2+
Fix from $1,600 2025-12-15
Kodexplorer MEDIUM 6.1
CVE-2025-34504

KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers c…

No fix yet
Fix from $1,600 2025-12-11
Miniflux MEDIUM 6.1
CVE-2025-67713

Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs() is false, enabling phishin…

Fix: 2.2.15+
Fix from $1,600 2025-12-11