Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2021-25028 The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given va… Event Tickets 5.2.2+ Fix from $1,6002022-01-24 MEDIUM 6.1 CVE-2021-25074 The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirectin… Webp Converter For Media 4.0.3+ Fix from $1,6002022-01-24 MEDIUM 6.1 CVE-2021-24838 The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function wit… Anycomment 0.3.5+ Fix from $1,6002022-01-17 MEDIUM 6.1 CVE-2022-0235 node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor Debian Linux 1.0 / 2.6.7+ Fix from $1,6002022-01-16 MEDIUM 6.1 CVE-2021-38678 An open redirect vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows attackers to redire… Qcalagent 1.1.7+ Fix from $1,6002022-01-14 MEDIUM 6.1 CVE-2021-44528 A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with c… Rails Patch available Fix from $1,6002022-01-10 MEDIUM 6.1 CVE-2022-0122 forge is vulnerable to URL Redirection to Untrusted Site Forge 1.0.0+ Fix from $1,6002022-01-06 MEDIUM 6.1 CVE-2022-21651 Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to… Shopware 5.7.7+ Fix from $1,6002022-01-05 MEDIUM 6.1 CVE-2021-20875 Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.… Groupsession after 5.1.1 Fix from $1,6002021-12-24 MEDIUM 6.1 CVE-2021-40852 TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the atta… Gim Mitigation only Fix from $1,6002021-12-17 MEDIUM 6.1 CVE-2021-43812 The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain retu… Nextjs Auth0 1.6.2+ Fix from $1,6002021-12-16 MEDIUM 6.1 CVE-2020-18985 An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their c… Zimbra Collaboration Suite Mitigation only Fix from $1,6002021-12-15 MEDIUM 6.1 CVE-2021-3829 openwhyd is vulnerable to URL Redirection to Untrusted Site Openwhyd 1.45.3+ Fix from $1,6002021-12-10 MEDIUM 6.1 CVE-2021-43532 The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows -… Firefox 94.0+ Fix from $1,6002021-12-08 MEDIUM 6.1 CVE-2021-43064 A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below… Fortiweb after 6.3.15 Fix from $1,6002021-12-08 MEDIUM 5.4 CVE-2021-36191 A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the devic… Fortiweb after 6.3.15 Fix from $1,6002021-12-08 MEDIUM 6.1 CVE-2021-4000 showdoc is vulnerable to URL Redirection to Untrusted Site Showdoc Patch available Fix from $1,6002021-12-03 MEDIUM 6.1 CVE-2021-3989 showdoc is vulnerable to URL Redirection to Untrusted Site Showdoc 2.9.13+ Fix from $1,6002021-12-01 MEDIUM 5.4 CVE-2021-42564 An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confi… Cryptshare Server 5.1.0+ Fix from $1,6002021-11-30 MEDIUM 6.1 CVE-2021-43777 Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly … Redash after 10.0.0 Fix from $1,6002021-11-24 MEDIUM 6.1 CVE-2021-38000 KEV Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily brow… Chrome 95.0.4638.69+ Fix from $1,6002021-11-23 MEDIUM 5.4 CVE-2021-36332 Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentiall… Emc Cloud Link 7.1.1+ Fix from $1,6002021-11-23 MEDIUM 6.1 CVE-2021-41733 Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them. Oppia Patch available Fix from $1,6002021-11-08 MEDIUM 6.1 CVE-2021-1500 A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to… Collaboration Meeting Rooms 2021.10.18.2439m+ Fix from $1,6002021-11-04 MEDIUM 6.1 CVE-2021-43058 An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exploit this vulnerability, an a… Replicated Classic 2.53.1+ Fix from $1,6002021-11-01 MEDIUM 6.1 CVE-2021-34764 Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute… Firepower Management Center Virtual Appliance 6.4.0.13 / 6.6.5+ Fix from $1,6002021-10-27 MEDIUM 5.4 CVE-2021-3851 firefly-iii is vulnerable to URL Redirection to Untrusted Site Firefly Iii 5.6.2+ Fix from $1,6002021-10-19 MEDIUM 6.1 CVE-2021-22942 A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a… Rails 6.0.4.1 / 6.1.4.1+ Fix from $1,6002021-10-18 MEDIUM 6.1 CVE-2021-22963 A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double sl… Fastify Static 4.2.4+ Fix from $1,6002021-10-14 HIGH 8.8 CVE-2021-22964 A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arb… Fastify Static 4.4.1+ Fix from $1,9502021-10-14