Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2025-61606
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identi…
Wegia
3.5.0+
MEDIUM 6.1
CVE-2025-54088
CVE-2025-54088 is an open-redirect vulnerability in Secure
Access prior to version 14.10. Attackers with access to the console can
redirect victims t…
Secure Access
14.10+
HIGH 7.2
CVE-2025-11240
An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legi…
Business Hub
1.16.0+
MEDIUM 6.1
CVE-2025-61587
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblat…
Weblate
5.13.3+
HIGH 7.5
CVE-2024-55017
Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to intercept auth…
Mitigation only
MEDIUM 6.1
CVE-2025-57878
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a …
Portal For Arcgis
Patch available
MEDIUM 6.1
CVE-2025-57879
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a …
Portal For Arcgis
Patch available
MEDIUM 6.1
CVE-2025-57872
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a …
Portal For Arcgis
Patch available
MEDIUM 5.4
CVE-2025-9072
Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft …
Mattermost Server
10.5.10 / 10.9.5+
MEDIUM 6.1
CVE-2025-9084
Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted …
Mattermost Server
10.5.10+
MEDIUM 6.1
CVE-2025-43795
Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA th…
Digital Experience Platform
7.3 / 7.4.3.102+
MEDIUM 6.4
CVE-2025-57665
Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction…
Element Plus
after 2.10.6
MEDIUM 6.1
CVE-2025-59013
An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.…
TYPO3
9.5.55 / 10.4.54+
MEDIUM 6.1
CVE-2025-20291
A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untru…
Webex Meetings
Mitigation only
MEDIUM 6.3
CVE-2024-12924
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing.
This issue affects QR Menü…
Mitigation only
HIGH 7.1
CVE-2025-20317
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unaut…
Mitigation only
CRITICAL 9.3
CVE-2025-2697
IBM Cognos Command Center 10.2.4.1 and 10.2.5
could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi…
Cognos Command Center
Mitigation only
MEDIUM 6.5
CVE-2025-52219
SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to create arb…
Selectzero
2025.5.2+
MEDIUM 6.1
CVE-2025-43767
Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 th…
Digital Experience Platform
7.4.3.132 / 2024.Q1.13+
HIGH 8.8
CVE-2025-57800
Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect …
Audiobookshelf
2.28.0+
MEDIUM 5.3
CVE-2025-55624
An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-public com…
Reolink
No fix yet
MEDIUM 6.3
CVE-2025-55625
An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is …
Reolink
No fix yet
MEDIUM 5.1
CVE-2025-55751
OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the University of Central Florida. A…
Patch available
MEDIUM 6.5
CVE-2025-7777
The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirec…
Mitigation only
CRITICAL 9.8
CVE-2025-55031
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …
Firefox
142.0+
MEDIUM 6.1
CVE-2025-55032
Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowin…
Firefox Focus
142.0+
MEDIUM 5.4
CVE-2025-54144
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal p…
Firefox
141.0+
CRITICAL 9.1
CVE-2025-54145
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text UR…
Firefox
141.0+
MEDIUM 5.5
CVE-2025-55207
Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerability in a subset of Astro depl…
Patch available
MEDIUM 5.1
CVE-2025-55166
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method only searches for lower-case…
Patch available