Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-6089
A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability affects unknown code of the fi…
Ishare Maps
Mitigation only
MEDIUM 6.1
CVE-2024-1440
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint …
Api Manager
Mitigation only
HIGH 8.8
CVE-2025-48936
Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the passw…
Zitadel
2.70.12 / 2.71.11+
MEDIUM 5.4
CVE-2025-5256
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an att…
Mitigation only
MEDIUM 6.1
CVE-2025-23183
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
No fix yet
MEDIUM 6.1
CVE-2025-4123EPSS 98%
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to …
Grafana
10.4.18 / 11.2.9+
MEDIUM 6.1
CVE-2024-12561
The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0…
Mitigation only
MEDIUM 6.1
CVE-2025-47854
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
Teamcity
2025.03.2+
MEDIUM 6.1
CVE-2025-32962
Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated a…
Flask Appbuilder
4.6.2+
MEDIUM 6.1
CVE-2025-40630
Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domai…
Mail Server
Mitigation only
MEDIUM 6.1
CVE-2025-47789
Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attacker can craft a Horilla URL t…
Horilla
1.3.1+
MEDIUM 6.1
CVE-2024-6690
The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites
Wp Content Copy Protection \& No Right Click
15.3+
MEDIUM 6.1
CVE-2023-6786
The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, lead…
Payment Gateway For Telcell
2.0.4+
MEDIUM 6.1
CVE-2025-30010
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which…
Supplier Relationship Management
Mitigation only
HIGH 7.1
CVE-2025-40846
Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing attackers to redirect users t…
Mitigation only
MEDIUM 6.1
CVE-2025-46553
@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `…
Summaly
5.2.1+
MEDIUM 6.1
CVE-2025-4143
The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly valid…
Workers Oauth Provider
Patch available
MEDIUM 6.1
CVE-2025-3859
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick u…
Firefox Focus
138.0+
MEDIUM 6.1
CVE-2025-32970
XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to …
Xwiki
15.10.13 / 16.4.4+
MEDIUM 5.0
CVE-2025-2068
An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.
Mitigation only
MEDIUM 6.1
CVE-2020-36845
The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before …
Security Awareness Training
2020-01-10+
MEDIUM 6.3
CVE-2025-3522
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thu…
Thunderbird
128.9.2 / 137.0.2+
HIGH 8.6
CVE-2025-31491
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…
Autogpt Platform
0.6.1+
MEDIUM 6.1
CVE-2024-49706
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parame…
Iksoris
79.0+
MEDIUM 6.1
CVE-2025-3433
The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.1. This is due to insuf…
Mitigation only
HIGH 7.4
CVE-2025-3155EPSS 13%
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious …
Debian Linux
No fix yet
HIGH 8.1
CVE-2025-24180
The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.…
Safari
2.3 / 15.4+
MEDIUM 6.1
CVE-2025-3027
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, t…
Ejbca
9.1+
HIGH 8.8
CVE-2025-24381
Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker wi…
Unity Operating Environment
5.5.0.0.5.259+
MEDIUM 6.1
CVE-2025-30164
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…
Icinga Web 2
2.11.5 / 2.12.3+