Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2024-8897EPSS 7%
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to s…
Firefox
130.0.1+
MEDIUM 6.1
CVE-2024-8761
The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient vali…
Share This Image
2.04+
MEDIUM 6.1
CVE-2024-4283
An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under …
GitLab
17.1.7 / 17.2.5+
MEDIUM 6.1
CVE-2024-4612
An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under …
GitLab
17.1.7 / 17.2.5+
MEDIUM 6.1
CVE-2024-7312
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session…
Payara
4.1.2.191.50 / 5.67.0+
MEDIUM 6.1
CVE-2024-8646
In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed.
This vulnerability is caused by the vulner…
Glassfish
7.0.10+
MEDIUM 6.1
CVE-2024-7260
An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are m…
Build Of Keycloak
24.0.7+
MEDIUM 6.1
CVE-2024-8586
WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users,…
Webitr
2_1_0_28+
MEDIUM 6.1
CVE-2024-42341
Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Queuemetrics
24.05.5+
MEDIUM 6.1
CVE-2024-8555
A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown func…
Clinic\'s Patient Management System
No fix yet
MEDIUM 6.1
CVE-2024-8412
A vulnerability, which was classified as problematic, was found in LinuxOSsk Shakal-NG up to 1.3.3. Affected is an unknown function of the file comme…
Shakal Ng
after 1.3.3
MEDIUM 6.1
CVE-2024-8386
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofin…
Firefox
128.2 / 130.0+
MEDIUM 6.1
CVE-2024-44776
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.
Vtiger Crm
No fix yet
HIGH 8.2
CVE-2024-35133
IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open…
Security Verify Access
after 10.0.8
MEDIUM 6.1
CVE-2024-39097
There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.
Gnuboard
6.0.5+
MEDIUM 6.1
CVE-2024-43794
OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper vali…
Patch available
MEDIUM 6.1
CVE-2024-27184
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
Joomla\!
3.10.17 / 4.4.7+
MEDIUM 6.1
CVE-2024-6377
An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release …
3dexperience
Mitigation only
MEDIUM 6.1
CVE-2024-43280
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking syste…
Salon Booking System
10.9+
MEDIUM 6.1
CVE-2024-7902
A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /l…
Open Journal Systems
after 3.4.0-6
MEDIUM 6.1
CVE-2024-42353
WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by…
Webob
1.8.8+
HIGH 8.2
CVE-2024-38211
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Dynamics 365
Patch available
MEDIUM 6.1
CVE-2024-7211
The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attack…
Platform
Mitigation only
MEDIUM 5.4
CVE-2024-41955
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulner…
Mobile Security Framework
4.0.5+
MEDIUM 6.1
CVE-2024-41801
OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the default configuration of packaged …
Openproject
14.3.0+
MEDIUM 6.1
CVE-2024-6289
The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing a…
Wps Hide Login
1.9.16.4+
MEDIUM 6.1
CVE-2024-6149
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
Workspace
2404.1+
MEDIUM 6.1
CVE-2024-5492
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
Netscaler Application Delivery Controller
12.1-55.304 / 13.0-92.31+
MEDIUM 6.1
CVE-2024-37830
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.
Outline
after 0.76.1
MEDIUM 5.3
CVE-2024-4882
The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
Mitigation only