Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.1
CVE-2025-71405
chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct r…
No fix yet
MEDIUM 6.1
CVE-2026-73671
Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the u…
No fix yet
MEDIUM 6.9
CVE-2026-46688
The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can …
No fix yet
MEDIUM 5.9
CVE-2026-66773
A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which ma…
No fix yet
HIGH 7.0
CVE-2026-58230
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially …
No fix yet
MEDIUM 5.3
CVE-2026-54214
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the
“cType” URL parameter, which allows arbitrar…
No fix yet
MEDIUM 5.3
CVE-2026-54215
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the
“replyUrl” parameter. An attacker can exploit this vulnera…
No fix yet
MEDIUM 5.3
CVE-2026-12071
The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input,
which is appended to the redirect target in a 3…
No fix yet
MEDIUM 6.1
CVE-2026-66829
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force …
Htmlsanitizeex
1.5.3+
MEDIUM 6.1
CVE-2026-66370
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote a…
Htmlsanitizeex
1.5.3+
MEDIUM 5.4
CVE-2026-14219
URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources…
No fix yet
MEDIUM 6.5
CVE-2026-69087
The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action eva…
No fix yet
HIGH 7.1
CVE-2025-71403
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. At…
No fix yet
HIGH 7.5
CVE-2026-10545
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external w…
Planning Analytics Local
after 2.1.21
MEDIUM 6.1
CVE-2026-66414
Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users …
No fix yet
MEDIUM 5.4
CVE-2026-18266
Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affe…
No fix yet
HIGH 8.6
CVE-2026-54603
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relati…
Mitigation only
HIGH 7.8
CVE-2026-67178
MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect:
Redirect p…
No fix yet
MEDIUM 6.1
CVE-2026-14171
An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website.…
No fix yet
MEDIUM 6.9
CVE-2026-53668
React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable…
React Router
7.13.0+
MEDIUM 6.1
CVE-2026-53669
React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNaviga…
React Router
7.18.0+
MEDIUM 6.1
CVE-2026-64645
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a
rewrites() o…
Next.js
15.5.21 / 16.2.11+
CRITICAL 9.3
CVE-2026-8152
Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack.
When Unblu Spark is dep…
No fix yet
MEDIUM 5.4
CVE-2026-62563
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecte…
Work In Process
after 12.2.15
MEDIUM 5.3
CVE-2026-62517
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a…
E Business Suite
after 12.2.15
MEDIUM 6.1
CVE-2026-62444
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a…
E Business Suite
after 12.2.15
MEDIUM 5.4
CVE-2026-61254
Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Korean Payroll). Supported versions that are aff…
Human Resources Management System
after 12.2.15
HIGH 7.6
CVE-2026-61181
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). …
Agile Product Lifecycle Management For Process
No fix yet
MEDIUM 6.4
CVE-2026-61143
Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions …
Communications Convergent Charging Controller
No fix yet
CRITICAL 9.6
CVE-2026-61097
Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supporte…
Banking Trade Finance Process Management
Mitigation only