Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2022-41275
In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in …
Solution Manager
Mitigation only
MEDIUM 6.1
CVE-2022-37927
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD).
Oneview Global Dashboard
2.7+
MEDIUM 6.1
CVE-2022-46683
Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkin…
Google Login
1.7+
MEDIUM 6.1
CVE-2022-45917
ILIAS before 7.16 has an Open Redirect.
Ilias
7.16+
CRITICAL 9.3
CVE-2022-41559
The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows an unauthenticated attacker w…
Nimbus
Mitigation only
MEDIUM 6.1
CVE-2022-43479
Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and c…
Shirasagi
after 1.15.0
MEDIUM 6.1
CVE-2022-41965
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 12.5, Opencast's Paella …
Opencast
12.5+
MEDIUM 6.1
CVE-2021-22141
An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in…
Kibana
6.8.16 / 7.13.0+
MEDIUM 6.1
CVE-2022-38201
An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticate…
Arcgis Quickcapture
after 10.9.1
MEDIUM 6.1
CVE-2022-45402EPSS 82%
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.
Airflow
2.4.3+
MEDIUM 6.1
CVE-2022-3486
An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allow…
GitLab
15.3.5 / 15.4.4+
MEDIUM 6.1
CVE-2022-3280
An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker …
GitLab
15.3.5 / 15.4.4+
MEDIUM 5.3
CVE-2022-44560
The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modif…
Emui
Mitigation only
MEDIUM 6.1
CVE-2022-41207
SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsens…
Biller Direct
No fix yet
MEDIUM 6.1
CVE-2022-43985
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.
Airflow
2.4.2+
MEDIUM 6.1
CVE-2022-3797
A vulnerability was found in eolinker apinto-dashboard. It has been rated as problematic. This issue affects some unknown processing of the file /log…
Apinto Dashboard
No fix yet
CRITICAL 9.6
CVE-2022-28763
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a …
Meetings
5.12.2+
MEDIUM 6.1
CVE-2022-39021
U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vulnerability to redirect user …
U Office Force
after 20.50.7821d
MEDIUM 6.5
CVE-2022-39359
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL…
Metabase
0.41.9 / 0.42.6+
MEDIUM 6.1
CVE-2022-38197
Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user int…
Arcgis Server
after 10.9.1
MEDIUM 6.1
CVE-2022-26954
Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to …
Nopcommerce
4.50.2+
HIGH 8.8
CVE-2022-41204
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject …
Commerce
Mitigation only
MEDIUM 6.1
CVE-2022-3438
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
Rdiffweb
2.5.0+
CRITICAL 9.6
CVE-2022-40083
Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged b…
Echo
Patch available
HIGH 8.2
CVE-2022-39258
mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Author…
Mailcow\
2022-09+
MEDIUM 6.1
CVE-2022-28977
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack …
Digital Experience Platform
7.4.3.4+
MEDIUM 6.1
CVE-2022-40754
In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.
Airflow
after 2.3.4
MEDIUM 6.1
CVE-2022-31735
OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected …
Openam
after 14.2.0-2
MEDIUM 6.1
CVE-2022-39814
In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.
1350 Optical Management System
Mitigation only
MEDIUM 5.4
CVE-2022-25295
This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The applicatio…
Gophish
0.12.0+