Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-8813
A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as problematic. This vulnerability affects the function changeLanguage of th…
Pybbs
after 6.0.0
MEDIUM 6.1
CVE-2025-54793
Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash…
Astro
5.12.7+
HIGH 7.4
CVE-2025-2824
IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an…
Operational Decision Manager
Mitigation only
MEDIUM 6.3
CVE-2024-34328
An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.
Mitigation only
CRITICAL 9.8
CVE-2025-50578
LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Refer…
Docker Heimdall
Mitigation only
MEDIUM 6.1
CVE-2025-52897
GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to atte…
Glpi
10.0.19+
MEDIUM 5.1
CVE-2025-54414
Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to protect upstream resources fr…
Patch available
MEDIUM 6.1
CVE-2025-8129
A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.j…
Koa
2.16.2+
MEDIUM 5.4
CVE-2025-44109
A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.
Mitigation only
MEDIUM 5.4
CVE-2025-50477
A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.
Mitigation only
MEDIUM 6.1
CVE-2025-7953
A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS up to 5.202506.a. This issue affects some unknown processin…
Publiccms
5.202506.b+
MEDIUM 6.1
CVE-2025-7949
A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerability is an unknown fu…
Publiccms
5.202506.b+
HIGH 7.6
CVE-2025-6023EPSS 39%
An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in G…
Mitigation only
CRITICAL 9.0
CVE-2025-50067
Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5.…
Application Express
Patch available
MEDIUM 6.1
CVE-2025-53821
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirect vulnerability exists in the…
Wegia
3.4.5+
MEDIUM 6.1
CVE-2025-42981
Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malici…
Mitigation only
MEDIUM 6.1
CVE-2025-42985
Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts…
Mitigation only
MEDIUM 6.1
CVE-2024-37656
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter veri…
Gnuboard
No fix yet
MEDIUM 6.1
CVE-2024-37657
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component.
Gnuboard
Patch available
MEDIUM 6.1
CVE-2024-37658
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.
Gnuboard
Patch available
HIGH 8.0
CVE-2025-6238
The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect…
Ai Engine
Patch available
MEDIUM 5.4
CVE-2025-49592
n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be red…
N8n
1.98.0+
MEDIUM 6.1
CVE-2025-6701
A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-sso 1.1.0. This issue affects some unknown processing of the file…
Xxl Sso
No fix yet
MEDIUM 5.4
CVE-2025-25012
URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via …
Kibana
7.17.29 / 8.17.8+
HIGH 8.2
CVE-2025-36016
IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vi…
Process Mining
Mitigation only
MEDIUM 6.1
CVE-2025-52552
FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based…
Fastgpt
4.9.12+
MEDIUM 6.1
CVE-2025-6286
A vulnerability classified as problematic has been found in PHPGurukul COVID19 Testing Management System 2021. Affected is an unknown function of the…
Covid19 Testing Management System
Mitigation only
MEDIUM 6.1
CVE-2025-50182
urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browse…
Urllib3
2.5.0+
MEDIUM 6.1
CVE-2025-50181
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a Po…
Urllib3
2.5.0+
MEDIUM 5.4
CVE-2025-2091
An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously craf…
M Files Mobile
25.6.0+