Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2015-10112 A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_scr… Wooframework Branding after 1.0.1 Fix from $1,6002023-06-05 MEDIUM 6.1 CVE-2023-29540 Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <cod… Firefox 112.0+ Fix from $1,6002023-06-02 HIGH 8.1 CVE-2023-25734 After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpecte… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 MEDIUM 6.1 CVE-2023-32218 Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') Ix Workforce Engagement Mitigation only Fix from $1,6002023-05-30 MEDIUM 6.1 CVE-2023-23754 An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection s… Joomla\! 4.3.2+ Fix from $1,6002023-05-30 MEDIUM 6.1 CVE-2023-20884 VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to… Identity Manager after 22.09.1.0 Fix from $1,6002023-05-30 MEDIUM 6.1 CVE-2023-28370 Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web sit… Tornado 6.3.2+ Fix from $1,6002023-05-25 MEDIUM 6.1 CVE-2023-31245 Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impers… Orvc 7.3.0+ Fix from $1,6002023-05-22 MEDIUM 6.1 CVE-2023-32068EPSS 55% XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible t… Xwiki 14.10.4+ Fix from $1,6002023-05-15 MEDIUM 6.1 CVE-2023-25829 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a … Portal For Arcgis No fix yet Fix from $1,6002023-05-09 MEDIUM 5.4 CVE-2023-31134 Tauri is software for building applications for multi-platform deployment. The Tauri IPC is usually strictly isolated from external websites, but in … Tauri 1.0.9 / 1.1.4+ Fix from $1,6002023-05-09 MEDIUM 6.1 CVE-2020-21038 Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php. Typecho No fix yet Fix from $1,6002023-05-08 MEDIUM 5.4 CVE-2023-0155 An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitr… GitLab 15.8.5 / 15.9.5+ Fix from $1,6002023-05-03 MEDIUM 5.4 CVE-2023-2000 Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website Mattermost Desktop after 5.2.2 Fix from $1,6002023-05-02 MEDIUM 6.1 CVE-2015-10104 A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some … Icons For Features Patch available Fix from $1,6002023-04-30 MEDIUM 6.1 CVE-2023-22729 Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an at… Framework 4.12.5+ Fix from $1,6002023-04-26 MEDIUM 6.1 CVE-2023-26494 lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login page of the lorawan stack serve… Lorawan Stack 3.24.1+ Fix from $1,6002023-04-24 MEDIUM 6.1 CVE-2015-10102 A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this issue is some unknown functi… Freshdesk Patch available Fix from $1,6002023-04-17 MEDIUM 6.1 CVE-2023-29204 XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put i… Xwiki 13.10.10 / 14.4.4+ Fix from $1,6002023-04-15 MEDIUM 6.1 CVE-2022-46886 There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domai… Servicenow Mitigation only Fix from $1,6002023-04-14 MEDIUM 6.1 CVE-2023-24935 Microsoft Edge (Chromium-based) Spoofing Vulnerability Edge Chromium 112.0.5615.49+ Fix from $1,6002023-04-11 MEDIUM 5.4 CVE-2023-22641 A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS v… Fortiproxy 6.4.13 / 7.0.9+ Fix from $1,6002023-04-11 MEDIUM 5.4 CVE-2023-28069 Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to re… Streaming Data Platform 1.4+ Fix from $1,6002023-04-05 HIGH 7.4 CVE-2022-48358 The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerability by a malicious app can cause service excepti… Emui No fix yet Fix from $1,9502023-03-27 MEDIUM 6.1 CVE-2022-2237 A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso functio… Keycloak Node.js Adapter Mitigation only Fix from $1,6002023-03-27 MEDIUM 6.1 CVE-2023-28628 lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an attacker to send malicious UR… Uri 1.14.120+ Fix from $1,6002023-03-27 MEDIUM 6.1 CVE-2016-15030 A vulnerability classified as problematic has been found in Arno0x TwoFactorAuth. This affects an unknown part of the file login/login.php. The manip… Twofactorauth 2016-01-27+ Fix from $1,6002023-03-25 MEDIUM 5.4 CVE-2023-22259 Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privile… Experience Manager 6.5.16.0 / 2023.1.0+ Fix from $1,6002023-03-22 MEDIUM 5.4 CVE-2023-22260 Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privile… Experience Manager 6.5.16.0 / 2023.1.0+ Fix from $1,6002023-03-22 MEDIUM 5.4 CVE-2023-22261 Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privile… Experience Manager 6.5.16.0 / 2023.1.0+ Fix from $1,6002023-03-22