Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2022-28923 Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted UR… Caddy Patch available Fix from $1,6002023-02-06 MEDIUM 6.1 CVE-2023-22418 On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirec… Big Ip Access Policy Manager 14.1.5.3 / 15.1.7+ Fix from $1,6002023-02-01 MEDIUM 6.1 CVE-2023-24445 Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins. Openid after 2.4 Fix from $1,6002023-01-26 MEDIUM 6.1 CVE-2023-24044 A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host… Obsidian after 18.0.49 Fix from $1,6002023-01-22 MEDIUM 6.1 CVE-2023-22298 Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site… Pgadmin 4 6.14+ Fix from $1,6002023-01-17 MEDIUM 5.4 CVE-2022-43721 An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site wh… Superset after 1.5.2 Fix from $1,6002023-01-16 MEDIUM 6.1 CVE-2015-10052 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in calesanz gibb-modul-151. This affects the function… Gibb Modul 151 2015-03-19+ Fix from $1,6002023-01-15 MEDIUM 6.1 CVE-2022-39183 Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors. Saml Authentication Mitigation only Fix from $1,6002023-01-12 MEDIUM 6.1 CVE-2023-0042 An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.… GitLab 15.5.7 / 15.6.4+ Fix from $1,6002023-01-12 MEDIUM 6.1 CVE-2023-22958 The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidati… Secure Login 3.1.1.0+ Fix from $1,6002023-01-11 MEDIUM 6.1 CVE-2017-20164 A vulnerability was found in Symbiote Seed up to 6.0.2. It has been classified as critical. Affected is the function onBeforeSecurityLogin of the fil… Seed 6.0.3+ Fix from $1,6002023-01-07 MEDIUM 6.1 CVE-2022-3614 In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and … Octopus Server 2022.3.10750 / 2022.4.8063+ Fix from $1,6002023-01-03 MEDIUM 6.1 CVE-2022-38208 There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a UR… Portal For Arcgis after 11.0 Fix from $1,6002022-12-29 MEDIUM 6.1 CVE-2022-4720 Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5. Rdiffweb 2.5.5+ Fix from $1,6002022-12-27 MEDIUM 6.1 CVE-2020-36627 A vulnerability was found in Macaron i18n. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the fil… I18n 0.5.0+ Fix from $1,6002022-12-25 MEDIUM 6.1 CVE-2022-45413 Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be… Firefox 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-36316 When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL ha… Firefox 103.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-34474 Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol… Firefox 102.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-34478 The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser,… Firefox 91.11 / 102.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-29912 Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefo… Firefox 91.9 / 100.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-29910 When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Fi… Firefox 100.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-4644 Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4. Rdiffweb 2.5.4+ Fix from $1,6002022-12-22 MEDIUM 5.4 CVE-2022-44488 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privi… Experience Manager 6.5.15.0 / 2022.10.0+ Fix from $1,6002022-12-19 MEDIUM 6.1 CVE-2021-4260 A vulnerability was found in oils-js. It has been declared as critical. This vulnerability affects unknown code of the file core/Web.js. The manipula… Oils Js 2021-03-23+ Fix from $1,6002022-12-19 MEDIUM 6.1 CVE-2022-47500 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache H… Helix after 1.0.4 Fix from $1,6002022-12-19 MEDIUM 6.1 CVE-2022-38662  In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites. Hcl Digital Experience Mitigation only Fix from $1,6002022-12-19 MEDIUM 6.1 CVE-2022-46288 Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitr… Electronic Bidding Core System after 6 Fix from $1,6002022-12-19 MEDIUM 6.1 CVE-2022-4589 A vulnerability has been found in cyface Terms and Conditions Module up to 2.0.9 and classified as problematic. Affected by this vulnerability is the… Django Terms And Conditions 2.0.10+ Fix from $1,6002022-12-17 MEDIUM 6.1 CVE-2022-23527 mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulne… Debian Linux 2.4.12.2+ Fix from $1,6002022-12-14 MEDIUM 6.1 CVE-2022-41273 Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicio… Contract Lifecycle Manager Mitigation only Fix from $1,6002022-12-13