Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2023-5610
The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary r…
Seraphinite Accelerator
2.2.29+
MEDIUM 5.4
CVE-2023-5445
An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter …
Epolicy Orchestrator
5.10.0+
MEDIUM 6.1
CVE-2023-41699
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation module…
Payara
4.1.2.191.46 / 5.57.0+
MEDIUM 6.1
CVE-2023-5986
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting att…
Ecostruxure Power Monitoring Expert
Mitigation only
MEDIUM 6.1
CVE-2019-25155
DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
Dompurify
1.0.11+
MEDIUM 6.1
CVE-2023-45203
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacke…
Online Examination System
No fix yet
MEDIUM 6.1
CVE-2023-45202
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker…
Online Examination System
No fix yet
MEDIUM 6.1
CVE-2023-45201
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacke…
Online Examination System
No fix yet
MEDIUM 6.1
CVE-2023-20264
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive S…
Adaptive Security Appliance Software
after 9.19.1.12
MEDIUM 6.1
CVE-2023-20886
VMware Workspace ONE UEM console contains an open redirect vulnerability.
A malicious actor may be able to redirect a victim to an attacker and ret…
Workspace One Uem
22.3.0.48 / 22.6.0.36+
MEDIUM 6.1
CVE-2023-4964
Potential open redirect vulnerability
in opentext Service Management Automation X
(SMAX) versions 2020.05, 2020.08,
2020.11, 2021.02, 2021.05, 2021.…
Asset Management X
Mitigation only
MEDIUM 6.1
CVE-2023-36085
The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By…
Sisqualwfm
7.1.319.111+
MEDIUM 6.1
CVE-2021-46898
views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does …
Django Grappelli
2.15.2+
MEDIUM 6.1
CVE-2023-45909
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
Zzzphp
Patch available
MEDIUM 6.1
CVE-2018-25091
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, po…
Urllib3
1.24.2+
MEDIUM 6.1
CVE-2023-5375EPSS 35%
Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.
Mosparo
1.0.2+
HIGH 7.1
CVE-2023-3922
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all ve…
GitLab
16.2.8 / 16.3.5+
MEDIUM 5.4
CVE-2023-23957
An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4
Identity Portal
No fix yet
MEDIUM 6.1
CVE-2023-40779
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.
Deep Castle G2
Mitigation only
MEDIUM 6.1
CVE-2023-41609
An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site v…
Couchcms
No fix yet
MEDIUM 6.1
CVE-2023-40306
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient UR…
S\/4hana
Mitigation only
MEDIUM 6.1
CVE-2023-20263
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect…
Hyperflex Hx Data Platform
Mitigation only
MEDIUM 5.4
CVE-2023-39364
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console access can be redirected to an arb…
Fedora
No fix yet
MEDIUM 6.1
CVE-2023-38574
Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and con…
Video Insight
7.9.6+
MEDIUM 6.1
CVE-2023-39371
StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601)
Softswitch
Mitigation only
MEDIUM 6.1
CVE-2023-1279
An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all ver…
GitLab
16.1.5 / 16.2.5+
MEDIUM 6.1
CVE-2023-39968
jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can…
Jupyter Server
2.7.2+
MEDIUM 6.1
CVE-2023-41080EPSS 6%
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from…
Tomcat
after 10.1.12
MEDIUM 6.1
CVE-2022-45582
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
Horizon
after 20.1.4
MEDIUM 6.1
CVE-2022-44215
There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.
Titan Ftp Server
after 19.0