Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2024-8897EPSS 7% Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to s… Firefox 130.0.1+ Fix from $1,6002024-09-17 MEDIUM 6.1 CVE-2024-8761 The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient vali… Share This Image 2.04+ Fix from $1,6002024-09-17 MEDIUM 6.1 CVE-2024-4283 An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under … GitLab 17.1.7 / 17.2.5+ Fix from $1,6002024-09-16 MEDIUM 6.1 CVE-2024-4612 An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under … GitLab 17.1.7 / 17.2.5+ Fix from $1,6002024-09-12 MEDIUM 6.1 CVE-2024-7312 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session… Payara 4.1.2.191.50 / 5.67.0+ Fix from $1,6002024-09-11 MEDIUM 6.1 CVE-2024-8646 In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulner… Glassfish 7.0.10+ Fix from $1,6002024-09-11 MEDIUM 6.1 CVE-2024-7260 An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are m… Build Of Keycloak 24.0.7+ Fix from $1,6002024-09-09 MEDIUM 6.1 CVE-2024-8586 WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users,… Webitr 2_1_0_28+ Fix from $1,6002024-09-09 MEDIUM 6.1 CVE-2024-42341 Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') Queuemetrics 24.05.5+ Fix from $1,6002024-09-08 MEDIUM 6.1 CVE-2024-8555 A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown func… Clinic\'s Patient Management System No fix yet Fix from $1,6002024-09-07 MEDIUM 6.1 CVE-2024-8412 A vulnerability, which was classified as problematic, was found in LinuxOSsk Shakal-NG up to 1.3.3. Affected is an unknown function of the file comme… Shakal Ng after 1.3.3 Fix from $1,6002024-09-04 MEDIUM 6.1 CVE-2024-8386 If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofin… Firefox 128.2 / 130.0+ Fix from $1,6002024-09-03 MEDIUM 6.1 CVE-2024-44776 An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL. Vtiger Crm No fix yet Fix from $1,6002024-08-29 HIGH 8.2 CVE-2024-35133 IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open… Security Verify Access after 10.0.8 Fix from $1,9502024-08-29 MEDIUM 6.1 CVE-2024-39097 There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path. Gnuboard 6.0.5+ Fix from $1,6002024-08-26 MEDIUM 6.1 CVE-2024-43794 OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper vali… Patch available Fix from $1,6002024-08-23 MEDIUM 6.1 CVE-2024-27184 Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.. Joomla\! 3.10.17 / 4.4.7+ Fix from $1,6002024-08-20 MEDIUM 6.1 CVE-2024-6377 An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release … 3dexperience Mitigation only Fix from $1,6002024-08-20 MEDIUM 6.1 CVE-2024-43280 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking syste… Salon Booking System 10.9+ Fix from $1,6002024-08-19 MEDIUM 6.1 CVE-2024-7902 A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /l… Open Journal Systems after 3.4.0-6 Fix from $1,6002024-08-17 MEDIUM 6.1 CVE-2024-42353 WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by… Webob 1.8.8+ Fix from $1,6002024-08-14 HIGH 8.2 CVE-2024-38211 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Dynamics 365 Patch available Fix from $1,9502024-08-13 MEDIUM 6.1 CVE-2024-7211 The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attack… Platform Mitigation only Fix from $1,6002024-08-01 MEDIUM 5.4 CVE-2024-41955 Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulner… Mobile Security Framework 4.0.5+ Fix from $1,6002024-07-31 MEDIUM 6.1 CVE-2024-41801 OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the default configuration of packaged … Openproject 14.3.0+ Fix from $1,6002024-07-25 MEDIUM 6.1 CVE-2024-6289 The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing a… Wps Hide Login 1.9.16.4+ Fix from $1,6002024-07-15 MEDIUM 6.1 CVE-2024-6149 Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5 Workspace 2404.1+ Fix from $1,6002024-07-10 MEDIUM 6.1 CVE-2024-5492 Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway Netscaler Application Delivery Controller 12.1-55.304 / 13.0-92.31+ Fix from $1,6002024-07-10 MEDIUM 6.1 CVE-2024-37830 An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie. Outline after 0.76.1 Fix from $1,6002024-07-09 MEDIUM 5.3 CVE-2024-4882 The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions. Mitigation only Fix from $1,6002024-07-08