Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2022-41275 In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in … Solution Manager Mitigation only Fix from $1,6002022-12-13 MEDIUM 6.1 CVE-2022-37927 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD). Oneview Global Dashboard 2.7+ Fix from $1,6002022-12-12 MEDIUM 6.1 CVE-2022-46683 Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkin… Google Login 1.7+ Fix from $1,6002022-12-12 MEDIUM 6.1 CVE-2022-45917 ILIAS before 7.16 has an Open Redirect. Ilias 7.16+ Fix from $1,6002022-12-07 CRITICAL 9.3 CVE-2022-41559 The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows an unauthenticated attacker w… Nimbus Mitigation only Fix from $2,3002022-12-06 MEDIUM 6.1 CVE-2022-43479 Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and c… Shirasagi after 1.15.0 Fix from $1,6002022-12-05 MEDIUM 6.1 CVE-2022-41965 Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 12.5, Opencast's Paella … Opencast 12.5+ Fix from $1,6002022-11-28 MEDIUM 6.1 CVE-2021-22141 An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in… Kibana 6.8.16 / 7.13.0+ Fix from $1,6002022-11-18 MEDIUM 6.1 CVE-2022-38201 An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticate… Arcgis Quickcapture after 10.9.1 Fix from $1,6002022-11-15 MEDIUM 6.1 CVE-2022-45402EPSS 82% In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint. Airflow 2.4.3+ Fix from $1,6002022-11-15 MEDIUM 6.1 CVE-2022-3486 An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allow… GitLab 15.3.5 / 15.4.4+ Fix from $1,6002022-11-09 MEDIUM 6.1 CVE-2022-3280 An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker … GitLab 15.3.5 / 15.4.4+ Fix from $1,6002022-11-09 MEDIUM 5.3 CVE-2022-44560 The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modif… Emui Mitigation only Fix from $1,6002022-11-09 MEDIUM 6.1 CVE-2022-41207 SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsens… Biller Direct No fix yet Fix from $1,6002022-11-08 MEDIUM 6.1 CVE-2022-43985 In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint. Airflow 2.4.2+ Fix from $1,6002022-11-02 MEDIUM 6.1 CVE-2022-3797 A vulnerability was found in eolinker apinto-dashboard. It has been rated as problematic. This issue affects some unknown processing of the file /log… Apinto Dashboard No fix yet Fix from $1,6002022-11-01 CRITICAL 9.6 CVE-2022-28763 The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a … Meetings 5.12.2+ Fix from $2,3002022-10-31 MEDIUM 6.1 CVE-2022-39021 U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vulnerability to redirect user … U Office Force after 20.50.7821d Fix from $1,6002022-10-31 MEDIUM 6.5 CVE-2022-39359 Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL… Metabase 0.41.9 / 0.42.6+ Fix from $1,6002022-10-26 MEDIUM 6.1 CVE-2022-38197 Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user int… Arcgis Server after 10.9.1 Fix from $1,6002022-10-25 MEDIUM 6.1 CVE-2022-26954 Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to … Nopcommerce 4.50.2+ Fix from $1,6002022-10-20 HIGH 8.8 CVE-2022-41204 An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject … Commerce Mitigation only Fix from $1,9502022-10-11 MEDIUM 6.1 CVE-2022-3438 Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. Rdiffweb 2.5.0+ Fix from $1,6002022-10-10 CRITICAL 9.6 CVE-2022-40083 Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged b… Echo Patch available Fix from $2,3002022-09-28 HIGH 8.2 CVE-2022-39258 mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Author… Mailcow\ 2022-09+ Fix from $1,9502022-09-27 MEDIUM 6.1 CVE-2022-28977 HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack … Digital Experience Platform 7.4.3.4+ Fix from $1,6002022-09-22 MEDIUM 6.1 CVE-2022-40754 In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint. Airflow after 2.3.4 Fix from $1,6002022-09-21 MEDIUM 6.1 CVE-2022-31735 OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected … Openam after 14.2.0-2 Fix from $1,6002022-09-15 MEDIUM 6.1 CVE-2022-39814 In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter. 1350 Optical Management System Mitigation only Fix from $1,6002022-09-13 MEDIUM 5.4 CVE-2022-25295 This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The applicatio… Gophish 0.12.0+ Fix from $1,6002022-09-11