Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2026-47002 Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that… Enterprise Manager Base Platform No fix yet Fix from $1,6002026-07-21 MEDIUM 6.1 CVE-2026-8284 URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue aff… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.1 CVE-2026-61901 Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect. No fix yet Fix from $1,6002026-07-20 HIGH 7.3 CVE-2026-32824 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.1 CVE-2026-7364 IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr… Security Verify Access after 11.0.2.0 Fix from $1,6002026-07-17 HIGH 8.1 CVE-2026-63094 SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session t… No fix yet Fix from $1,9502026-07-17 MEDIUM 6.8 CVE-2026-12379 An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not prop… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.1 CVE-2026-33213 Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's authentication module stripped… Redash Mitigation only Fix from $1,6002026-07-15 CRITICAL 9.6 CVE-2026-61451 The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/… Mitigation only Fix from $2,3002026-07-15 MEDIUM 6.1 CVE-2026-48784 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGen… Symfony 5.4.53 / 6.4.41+ Fix from $1,6002026-07-14 MEDIUM 6.1 CVE-2026-48000 Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could co… Commerce 1.21.0+ Fix from $1,6002026-07-14 MEDIUM 6.1 CVE-2026-45065 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGen… Symfony 5.4.52 / 6.4.40+ Fix from $1,6002026-07-14 MEDIUM 6.1 CVE-2026-14902 An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs. Xtraction 2026.2.1+ Fix from $1,6002026-07-14 HIGH 8.1 CVE-2026-44745 SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthent… Mitigation only Fix from $1,9502026-07-14 MEDIUM 5.9 CVE-2026-55806 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versi… Drupal 10.5.12 / 10.6.11+ Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-55461 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer h… Snipe It 8.6.2+ Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-55590 CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, … Cakephp 2.11.1 / 3.3.6+ Fix from $1,6002026-07-09 HIGH 7.1 CVE-2026-31982 An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirectio… Cmc 26.2.0+ Fix from $1,9502026-07-09 HIGH 7.4 CVE-2026-59806 Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URL… Patch available Fix from $1,9502026-07-08 MEDIUM 6.1 CVE-2026-55431 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder o… Coder 2.29.17 / 2.32.7+ Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-25779 Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values. Patch available Fix from $1,6002026-07-03 CRITICAL 9.3 CVE-2026-41106 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 365 Copilot Mitigation only Fix from $2,3002026-07-02 HIGH 7.6 CVE-2026-55660 Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich… Patch available Fix from $1,9502026-07-01 MEDIUM 6.1 CVE-2026-58520 URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Fl… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 MEDIUM 5.9 CVE-2026-10562 An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within t… Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-40080 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring che… Cacti 1.2.31+ Fix from $1,6002026-06-25 MEDIUM 5.4 CVE-2026-52802 Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where attacker-controlled redirect_to … Patch available Fix from $1,6002026-06-24 MEDIUM 5.3 CVE-2026-13163 Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mailerup <1.0.0 on all platforms… Patch available Fix from $1,6002026-06-24 CRITICAL 9.6 CVE-2026-54588 Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` requ… Mitigation only Fix from $2,3002026-06-23 MEDIUM 5.1 CVE-2026-47377 NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace() o… Mitigation only Fix from $1,6002026-06-23