Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2024-0953
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi…
Firefox Mobile
No fix yet
MEDIUM 5.4
CVE-2024-21794
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page.
Rapid Scada
after 5.8.4
MEDIUM 6.1
CVE-2023-6389EPSS 27%
The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated atta…
Wordpress Toolbar
after 2.2.6
HIGH 7.1
CVE-2023-6291
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful …
Keycloak
22.0.7+
MEDIUM 6.1
CVE-2024-22308
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/…
Simple Membership
4.4.2+
MEDIUM 5.4
CVE-2024-0854
URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8…
Diskstation Manager
7.2.1-69057-2+
MEDIUM 6.1
CVE-2024-0781
A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pa…
Internet Banking System
No fix yet
MEDIUM 6.1
CVE-2024-22113
Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to r…
Cgi An Anlyzer
after 2023-12-31
MEDIUM 5.4
CVE-2023-50963
IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST he…
Storage Defender Data Protect
after 1.4.1
MEDIUM 6.1
CVE-2024-22400
Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server a…
Sso \& Saml Authentication
5.1.5 / 5.2.5+
MEDIUM 6.1
CVE-2023-3771
The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.
T1
after 19.0
MEDIUM 6.1
CVE-2024-0319
Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user …
Hxtool
Mitigation only
MEDIUM 6.1
CVE-2024-0545
A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the…
Rise Ultimate Project Manager
Mitigation only
MEDIUM 6.1
CVE-2023-49394
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
Zentao
after 4.1.3
MEDIUM 5.4
CVE-2024-21734
SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very …
Marketing
Mitigation only
MEDIUM 6.1
CVE-2023-6552
Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.
Tasmoadmin
3.3.0+
MEDIUM 6.1
CVE-2023-50345
HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially l…
Dryice Myxalytics
Mitigation only
MEDIUM 6.1
CVE-2023-26159
Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.pa…
Follow Redirects
1.15.4+
MEDIUM 6.1
CVE-2023-52263
Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_c…
Browser
1.59.40+
MEDIUM 5.4
CVE-2023-51517
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: fro…
Calculated Fields Form
after 1.2.28
MEDIUM 5.4
CVE-2023-51675
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Securi…
Advanced Access Manager
6.9.19+
MEDIUM 6.1
CVE-2023-32101
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pexle Chris Library Viewer.This issue affects Library Viewer: from n/a through 2…
Library Viewer
2.0.6.1+
MEDIUM 6.1
CVE-2023-32517
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder.T…
Mailchimp
4.0.9.4+
MEDIUM 6.1
CVE-2023-31095
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja …
Database For Contact Form 7\, Wpforms\, Elementor Forms
1.2.9+
MEDIUM 6.1
CVE-2023-31229
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP Directory Kit.This issue affects WP Directory Kit: from n/a through 1.1.9.
Wp Directory Kit
1.2.0+
MEDIUM 6.1
CVE-2023-31237
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: fr…
Zephyr Project Manager
3.3.91+
MEDIUM 6.1
CVE-2023-28786
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authentication, and Brute Force Pr…
Solid Security
after 8.1.4
MEDIUM 6.1
CVE-2023-48003
An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any UR…
Asp.net Zero
12.3.0+
MEDIUM 6.1
CVE-2023-49438
An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites vi…
Flask Security Too
after 5.3.2
MEDIUM 6.1
CVE-2023-50297
Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary we…
Powercms
4.55 / 5.25+