Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 5.1 CVE-2025-71405 chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct r… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.1 CVE-2026-73671 Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the u… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.9 CVE-2026-46688 The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can … No fix yet Fix from $4,0002026-08-13 MEDIUM 5.9 CVE-2026-66773 A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which ma… No fix yet Fix from $4,0002026-08-11 HIGH 7.0 CVE-2026-58230 SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially … No fix yet Fix from $4,9002026-08-11 MEDIUM 5.3 CVE-2026-54214 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrar… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2026-54215 Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnera… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2026-12071 The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 3… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.1 CVE-2026-66829 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force … Htmlsanitizeex 1.5.3+ Fix from $1,6002026-08-06 MEDIUM 6.1 CVE-2026-66370 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote a… Htmlsanitizeex 1.5.3+ Fix from $1,6002026-08-06 MEDIUM 5.4 CVE-2026-14219 URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.5 CVE-2026-69087 The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action eva… No fix yet Fix from $1,6002026-08-03 HIGH 7.1 CVE-2025-71403 better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. At… No fix yet Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-10545 IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external w… Planning Analytics Local after 2.1.21 Fix from $1,9502026-07-30 MEDIUM 6.1 CVE-2026-66414 Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users … No fix yet Fix from $1,6002026-07-30 MEDIUM 5.4 CVE-2026-18266 Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affe… No fix yet Fix from $1,6002026-07-29 HIGH 8.6 CVE-2026-54603 OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relati… Mitigation only Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-67178 MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect p… No fix yet Fix from $1,9502026-07-28 MEDIUM 6.1 CVE-2026-14171 An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website.… No fix yet Fix from $1,6002026-07-28 MEDIUM 6.9 CVE-2026-53668 React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable… React Router 7.13.0+ Fix from $1,6002026-07-27 MEDIUM 6.1 CVE-2026-53669 React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNaviga… React Router 7.18.0+ Fix from $1,6002026-07-27 MEDIUM 6.1 CVE-2026-64645 Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() o… Next.js 15.5.21 / 16.2.11+ Fix from $1,6002026-07-27 CRITICAL 9.3 CVE-2026-8152 Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is dep… No fix yet Fix from $2,3002026-07-22 MEDIUM 5.4 CVE-2026-62563 Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecte… Work In Process after 12.2.15 Fix from $1,6002026-07-21 MEDIUM 5.3 CVE-2026-62517 Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a… E Business Suite after 12.2.15 Fix from $1,6002026-07-21 MEDIUM 6.1 CVE-2026-62444 Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a… E Business Suite after 12.2.15 Fix from $1,6002026-07-21 MEDIUM 5.4 CVE-2026-61254 Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Korean Payroll). Supported versions that are aff… Human Resources Management System after 12.2.15 Fix from $1,6002026-07-21 HIGH 7.6 CVE-2026-61181 Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). … Agile Product Lifecycle Management For Process No fix yet Fix from $1,9502026-07-21 MEDIUM 6.4 CVE-2026-61143 Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions … Communications Convergent Charging Controller No fix yet Fix from $1,6002026-07-21 CRITICAL 9.6 CVE-2026-61097 Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supporte… Banking Trade Finance Process Management Mitigation only Fix from $2,3002026-07-21