Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2022-23237
E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker…
E Series Santricity Os Controller
after 11.70.2
MEDIUM 6.1
CVE-2022-29214
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vuln…
Next Auth
3.29.3 / 4.3.3+
HIGH 8.5
CVE-2022-29170
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to config…
Grafana
7.5.16 / 8.5.3+
MEDIUM 6.1
CVE-2022-1774
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
Drawio
18.0.7+
MEDIUM 6.1
CVE-2022-30992
Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
Cyber Protect
15+
MEDIUM 6.1
CVE-2022-1702EPSS 9%
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site …
Sma 6200 Firmware
Mitigation only
MEDIUM 6.1
CVE-2022-22797
Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" request from the url location: /Com…
Sysaid
22.1.50 / 22.1.64+
MEDIUM 5.4
CVE-2022-1209
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of…
Ultimate Member
after 2.3.1
MEDIUM 6.1
CVE-2021-44054
An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows …
Qts
4.3.3.1945 / 4.3.4.1976+
HIGH 8.1
CVE-2022-20764
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote …
Telepresence Collaboration Endpoint
10.8.2.5 / 2021-05+
MEDIUM 6.1
CVE-2022-27461
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafte…
Nopcommerce
after 4.50.1
MEDIUM 6.1
CVE-2022-26326
Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2
Netiq Access Manager
5.0.2+
MEDIUM 6.1
CVE-2022-24887
Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0…
Talk
11.3.4 / 12.2.4+
MEDIUM 6.1
CVE-2021-25111
The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leadi…
English Wordpress Admin
1.5.2+
MEDIUM 6.1
CVE-2020-14118
An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the…
Mi App Store
4.10.0+
MEDIUM 6.1
CVE-2022-1254
A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.…
Web Gateway
7.8.2.31 / 8.2.27+
MEDIUM 6.1
CVE-2022-24858
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2…
Next Auth
3.29.2 / 4.3.2+
MEDIUM 6.1
CVE-2022-1019
Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a ma…
Webctrl Server
after 7.0
MEDIUM 6.1
CVE-2022-0645
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.
Posthog
1.34.1+
MEDIUM 6.1
CVE-2020-25154
An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data…
Datamodule Compactplus
Mitigation only
MEDIUM 6.1
CVE-2022-27256
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files…
Hubzilla
7.2+
MEDIUM 5.4
CVE-2022-27109
OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
Orangehrm
No fix yet
MEDIUM 5.4
CVE-2022-27110
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
Orangehrm
No fix yet
MEDIUM 6.1
CVE-2022-27463
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url …
Avideo
after 11.6
MEDIUM 6.1
CVE-2022-1233
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
Uri.js
1.19.11+
MEDIUM 6.1
CVE-2022-24794
Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middle…
Express Openid Connect
2.7.2+
MEDIUM 6.1
CVE-2022-23798
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check wheth…
Joomla\!
after 4.1.0
MEDIUM 6.1
CVE-2022-26950
Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate…
Archer
6.9.0.3+
MEDIUM 6.1
CVE-2005-10001
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/s…
Symantec Siteminder
Mitigation only
MEDIUM 6.1
CVE-2022-0283
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a…
GitLab
14.5.4 / 14.6.4+