Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2024-5936EPSS 29%
An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allo…
Privategpt
No fix yet
MEDIUM 6.1
CVE-2024-4704
The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their…
Contact Form 7
5.9.5+
MEDIUM 6.1
CVE-2024-4604
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.
Th…
Mitigation only
MEDIUM 6.1
CVE-2024-4900
The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perf…
Seopress
7.8+
MEDIUM 6.1
CVE-2024-4940
An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users …
Gradio
No fix yet
MEDIUM 6.1
CVE-2024-3597
The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.2.2. This is due to…
Export Wp Page To Static Html\/css
after 2.2.2
MEDIUM 5.3
CVE-2024-37881
SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from …
Mitigation only
MEDIUM 6.1
CVE-2024-23442
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted …
Kibana
7.17.22 / 8.14.0+
MEDIUM 6.1
CVE-2024-3032
Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect iss…
Builder
7.5.8+
HIGH 8.1
CVE-2024-34065
Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query paramet…
Strapi
4.24.2+
MEDIUM 6.1
CVE-2024-22244
Open Redirect in Harbor <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.
Harbor
2.8.5 / 2.9.3+
MEDIUM 6.1
CVE-2024-36419
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host He…
Suitecrm
8.6.1+
MEDIUM 5.4
CVE-2024-36406
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows…
Suitecrm
7.14.4 / 8.6.1+
MEDIUM 6.1
CVE-2024-23664
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below …
Fortiauthenticator
6.5.4+
MEDIUM 6.1
CVE-2024-34071
Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected…
Umbraco Cms
8.18.14 / 10.8.6+
MEDIUM 6.1
CVE-2024-20369
A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote a…
Network Services Orchestrator
5.5.10.1 / 5.6.14.3+
HIGH 7.5
CVE-2024-4773
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfu…
Firefox
126.0+
MEDIUM 6.1
CVE-2023-6812
The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This…
Wp Compress
6.20.02+
MEDIUM 6.1
CVE-2024-34074
Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to u…
Frappe
14.74.0 / 15.26.0+
MEDIUM 6.1
CVE-2024-4133
The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Open Redirect …
Mitigation only
HIGH 8.8
CVE-2024-26504
An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst parameter.
Mitigation only
CRITICAL 9.1
CVE-2024-33661
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
Portainer
2.20.0+
MEDIUM 6.1
CVE-2022-36028
Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to …
Greenlight
2.13.0+
MEDIUM 6.1
CVE-2022-36029
Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to …
Greenlight
2.13.0+
HIGH 7.1
CVE-2024-2419
A flaw was found in Keycloak's redirect_uri validation logic. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attac…
Mitigation only
MEDIUM 6.1
CVE-2024-21065
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are …
Peoplesoft Enterprise Peopletools
Mitigation only
HIGH 8.1
CVE-2024-22262
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the …
Mitigation only
MEDIUM 6.5
CVE-2024-1183
An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports wi…
Gradio
4.11.0+
MEDIUM 6.1
CVE-2024-31282
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7.
App Builder
3.8.8+
MEDIUM 6.1
CVE-2024-31253
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4…
Wp Oauth Server
4.4.0+