Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2024-54051 Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker coul… Connect 11.4.9 / 12.7+ Fix from $1,6002024-12-10 MEDIUM 6.1 CVE-2024-52003 Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-… Traefik 2.11.14 / 3.2.1+ Fix from $1,6002024-11-29 MEDIUM 5.1 CVE-2024-53264 bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in the loading endpoint, allowin… Mitigation only Fix from $1,6002024-11-27 MEDIUM 5.9 CVE-2024-8526 A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when visited by an authenticated WebC… Mitigation only Fix from $1,6002024-11-21 MEDIUM 6.1 CVE-2024-52512 user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a p… User Oidc 6.1.0+ Fix from $1,6002024-11-15 MEDIUM 6.1 CVE-2022-20634 A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an unde… Enterprise Chat And Email 12.6+ Fix from $1,6002024-11-15 MEDIUM 6.1 CVE-2024-1240 An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the… Pyload Patch available Fix from $1,6002024-11-15 MEDIUM 5.4 CVE-2024-11207 A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the fil… Central Authentication Service No fix yet Fix from $1,6002024-11-14 MEDIUM 5.4 CVE-2024-30140 HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can p… Bigfix Compliance Mitigation only Fix from $1,6002024-11-07 MEDIUM 6.1 CVE-2024-50345 symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` c… Symfony 5.4.46 / 6.4.14+ Fix from $1,6002024-11-06 MEDIUM 6.5 CVE-2024-48463 Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer. Bruno 1.29.1+ Fix from $1,6002024-11-04 MEDIUM 6.1 CVE-2024-25566 An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attac… Access Management after 7.2.2 Fix from $1,6002024-10-29 MEDIUM 6.1 CVE-2024-42930 PbootCMS 3.2.8 is vulnerable to URL Redirect. Pbootcms Mitigation only Fix from $1,6002024-10-28 MEDIUM 6.1 CVE-2024-50463 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sun… Sunshine Photo Cart 3.2.11+ Fix from $1,6002024-10-28 MEDIUM 6.1 CVE-2024-49682 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allows Phishing.This issue affect… Simple Membership 4.5.4+ Fix from $1,6002024-10-24 MEDIUM 6.1 CVE-2024-46326 Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function. Mitigation only Fix from $1,6002024-10-21 MEDIUM 6.1 CVE-2024-47353 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in quomodosoft ElementsReady Addons for Elementor element-ready-lite.This issue aff… Elementsready 5.8.1+ Fix from $1,6002024-10-11 MEDIUM 6.1 CVE-2024-47648 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Metagauss EventPrime eventprime-event-calendar-management.This issue affects Eve… Eventprime 4.0.4.6+ Fix from $1,6002024-10-10 MEDIUM 6.8 CVE-2024-43543 Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows 10 1809 10.0.17763.6414 / 10.0.19044.5011+ Fix from $1,6002024-10-08 MEDIUM 6.8 CVE-2024-43536 Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows 10 1809 10.0.17763.6414 / 10.0.19044.5011+ Fix from $1,6002024-10-08 MEDIUM 6.1 CVE-2024-45247 Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect') Mitigation only Fix from $1,6002024-10-06 MEDIUM 6.1 CVE-2024-43683 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects T… Timeprovider 4100 Firmware 2.4.7+ Fix from $1,6002024-10-04 MEDIUM 6.1 CVE-2024-8148 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a … Portal For Arcgis Mitigation only Fix from $1,6002024-10-04 MEDIUM 6.1 CVE-2024-38037 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a … Portal For Arcgis Mitigation only Fix from $1,6002024-10-04 MEDIUM 6.1 CVE-2024-47530 Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users by redirecting them to malicio… Scout 4.89+ Fix from $1,6002024-09-30 MEDIUM 6.1 CVE-2024-9329 In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the reque… Glassfish 7.0.17+ Fix from $1,6002024-09-30 HIGH 7.2 CVE-2024-46331 ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows atta… Mostartcms No fix yet Fix from $1,9502024-09-27 HIGH 8.8 CVE-2024-45981 A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via user interaction with a crafte… Mitigation only Fix from $1,9502024-09-26 HIGH 8.8 CVE-2024-45979 A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via user interaction with a crafted… Mitigation only Fix from $1,9502024-09-26 MEDIUM 6.1 CVE-2024-8883 A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is se… Build Of Keycloak Mitigation only Fix from $1,6002024-09-19