Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2025-6089 A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability affects unknown code of the fi… Ishare Maps Mitigation only Fix from $1,6002025-06-15 MEDIUM 6.1 CVE-2024-1440 An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint … Api Manager Mitigation only Fix from $1,6002025-06-02 HIGH 8.8 CVE-2025-48936 Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the passw… Zitadel 2.70.12 / 2.71.11+ Fix from $1,9502025-05-30 MEDIUM 5.4 CVE-2025-5256 SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an att… Mitigation only Fix from $1,6002025-05-28 MEDIUM 6.1 CVE-2025-23183 CWE-601: URL Redirection to Untrusted Site ('Open Redirect') No fix yet Fix from $1,6002025-05-22 MEDIUM 6.1 CVE-2025-4123EPSS 98% A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to … Grafana 10.4.18 / 11.2.9+ Fix from $1,6002025-05-22 MEDIUM 6.1 CVE-2024-12561 The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0… Mitigation only Fix from $1,6002025-05-21 MEDIUM 6.1 CVE-2025-47854 In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page Teamcity 2025.03.2+ Fix from $1,6002025-05-20 MEDIUM 6.1 CVE-2025-32962 Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated a… Flask Appbuilder 4.6.2+ Fix from $1,6002025-05-16 MEDIUM 6.1 CVE-2025-40630 Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domai… Mail Server Mitigation only Fix from $1,6002025-05-16 MEDIUM 6.1 CVE-2025-47789 Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attacker can craft a Horilla URL t… Horilla 1.3.1+ Fix from $1,6002025-05-15 MEDIUM 6.1 CVE-2024-6690 The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites Wp Content Copy Protection \& No Right Click 15.3+ Fix from $1,6002025-05-15 MEDIUM 6.1 CVE-2023-6786 The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, lead… Payment Gateway For Telcell 2.0.4+ Fix from $1,6002025-05-15 MEDIUM 6.1 CVE-2025-30010 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which… Supplier Relationship Management Mitigation only Fix from $1,6002025-05-13 HIGH 7.1 CVE-2025-40846 Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing attackers to redirect users t… Mitigation only Fix from $1,9502025-05-08 MEDIUM 6.1 CVE-2025-46553 @misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `… Summaly 5.2.1+ Fix from $1,6002025-05-05 MEDIUM 6.1 CVE-2025-4143 The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly valid… Workers Oauth Provider Patch available Fix from $1,6002025-05-01 MEDIUM 6.1 CVE-2025-3859 Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick u… Firefox Focus 138.0+ Fix from $1,6002025-04-30 MEDIUM 6.1 CVE-2025-32970 XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to … Xwiki 15.10.13 / 16.4.4+ Fix from $1,6002025-04-30 MEDIUM 5.0 CVE-2025-2068 An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user. Mitigation only Fix from $1,6002025-04-25 MEDIUM 6.1 CVE-2020-36845 The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before … Security Awareness Training 2020-01-10+ Fix from $1,6002025-04-20 MEDIUM 6.3 CVE-2025-3522 Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thu… Thunderbird 128.9.2 / 137.0.2+ Fix from $1,6002025-04-15 HIGH 8.6 CVE-2025-31491 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio… Autogpt Platform 0.6.1+ Fix from $1,9502025-04-15 MEDIUM 6.1 CVE-2024-49706 Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parame… Iksoris 79.0+ Fix from $1,6002025-04-14 MEDIUM 6.1 CVE-2025-3433 The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.1. This is due to insuf… Mitigation only Fix from $1,6002025-04-08 HIGH 7.4 CVE-2025-3155EPSS 13% A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious … Debian Linux No fix yet Fix from $1,9502025-04-03 HIGH 8.1 CVE-2025-24180 The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.… Safari 2.3 / 15.4+ Fix from $1,9502025-03-31 MEDIUM 6.1 CVE-2025-3027 The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, t… Ejbca 9.1+ Fix from $1,6002025-03-31 HIGH 8.8 CVE-2025-24381 Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker wi… Unity Operating Environment 5.5.0.0.5.259+ Fix from $1,9502025-03-28 MEDIUM 6.1 CVE-2025-30164 Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1… Icinga Web 2 2.11.5 / 2.12.3+ Fix from $1,6002025-03-26