Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2024-0953 When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi… Firefox Mobile No fix yet Fix from $1,6002024-02-05 MEDIUM 5.4 CVE-2024-21794 In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page. Rapid Scada after 5.8.4 Fix from $1,6002024-02-02 MEDIUM 6.1 CVE-2023-6389EPSS 27% The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated atta… Wordpress Toolbar after 2.2.6 Fix from $1,6002024-01-29 HIGH 7.1 CVE-2023-6291 A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful … Keycloak 22.0.7+ Fix from $1,9502024-01-26 MEDIUM 6.1 CVE-2024-22308 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/… Simple Membership 4.4.2+ Fix from $1,6002024-01-24 MEDIUM 5.4 CVE-2024-0854 URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8… Diskstation Manager 7.2.1-69057-2+ Fix from $1,6002024-01-24 MEDIUM 6.1 CVE-2024-0781 A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pa… Internet Banking System No fix yet Fix from $1,6002024-01-22 MEDIUM 6.1 CVE-2024-22113 Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to r… Cgi An Anlyzer after 2023-12-31 Fix from $1,6002024-01-22 MEDIUM 5.4 CVE-2023-50963 IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST he… Storage Defender Data Protect after 1.4.1 Fix from $1,6002024-01-19 MEDIUM 6.1 CVE-2024-22400 Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server a… Sso \& Saml Authentication 5.1.5 / 5.2.5+ Fix from $1,6002024-01-18 MEDIUM 6.1 CVE-2023-3771 The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites. T1 after 19.0 Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2024-0319 Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user … Hxtool Mitigation only Fix from $1,6002024-01-15 MEDIUM 6.1 CVE-2024-0545 A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the… Rise Ultimate Project Manager Mitigation only Fix from $1,6002024-01-15 MEDIUM 6.1 CVE-2023-49394 Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly. Zentao after 4.1.3 Fix from $1,6002024-01-10 MEDIUM 5.4 CVE-2024-21734 SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very … Marketing Mitigation only Fix from $1,6002024-01-09 MEDIUM 6.1 CVE-2023-6552 Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerability. Tasmoadmin 3.3.0+ Fix from $1,6002024-01-08 MEDIUM 6.1 CVE-2023-50345 HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially l… Dryice Myxalytics Mitigation only Fix from $1,6002024-01-03 MEDIUM 6.1 CVE-2023-26159 Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.pa… Follow Redirects 1.15.4+ Fix from $1,6002024-01-02 MEDIUM 6.1 CVE-2023-52263 Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_c… Browser 1.59.40+ Fix from $1,6002023-12-30 MEDIUM 5.4 CVE-2023-51517 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: fro… Calculated Fields Form after 1.2.28 Fix from $1,6002023-12-29 MEDIUM 5.4 CVE-2023-51675 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Securi… Advanced Access Manager 6.9.19+ Fix from $1,6002023-12-29 MEDIUM 6.1 CVE-2023-32101 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pexle Chris Library Viewer.This issue affects Library Viewer: from n/a through 2… Library Viewer 2.0.6.1+ Fix from $1,6002023-12-29 MEDIUM 6.1 CVE-2023-32517 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder.T… Mailchimp 4.0.9.4+ Fix from $1,6002023-12-29 MEDIUM 6.1 CVE-2023-31095 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja … Database For Contact Form 7\, Wpforms\, Elementor Forms 1.2.9+ Fix from $1,6002023-12-29 MEDIUM 6.1 CVE-2023-31229 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP Directory Kit.This issue affects WP Directory Kit: from n/a through 1.1.9. Wp Directory Kit 1.2.0+ Fix from $1,6002023-12-29 MEDIUM 6.1 CVE-2023-31237 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: fr… Zephyr Project Manager 3.3.91+ Fix from $1,6002023-12-29 MEDIUM 6.1 CVE-2023-28786 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authentication, and Brute Force Pr… Solid Security after 8.1.4 Fix from $1,6002023-12-29 MEDIUM 6.1 CVE-2023-48003 An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any UR… Asp.net Zero 12.3.0+ Fix from $1,6002023-12-26 MEDIUM 6.1 CVE-2023-49438 An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites vi… Flask Security Too after 5.3.2 Fix from $1,6002023-12-26 MEDIUM 6.1 CVE-2023-50297 Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary we… Powercms 4.55 / 5.25+ Fix from $1,6002023-12-26