Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2021-24406
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect…
Wpforo Forum
1.9.7+
MEDIUM 6.1
CVE-2021-23401
This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user t…
Flask User
No fix yet
MEDIUM 6.1
CVE-2021-34807
An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker wo…
Collaboration
8.8.15+
MEDIUM 5.4
CVE-2020-23182
The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious …
Php Fusion
No fix yet
MEDIUM 6.1
CVE-2021-32721
PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to craft phishing links and othe…
Powermux
1.1.1+
MEDIUM 6.1
CVE-2021-20105
Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.
Machform
16+
MEDIUM 6.1
CVE-2021-34254
Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.
Umbraco Cms
7.15.7+
MEDIUM 6.1
CVE-2021-25655
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafte…
Aura Experience Portal
after 7.2.3
MEDIUM 6.1
CVE-2020-18660
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
Getsimplecms
after 3.3.15
MEDIUM 6.1
CVE-2021-35206
Gitpod before 0.6.0 allows unvalidated redirects.
Gitpod
0.6.0+
MEDIUM 6.1
CVE-2010-4266
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
Vanilla Forums
2.0.10+
MEDIUM 6.1
CVE-2021-32956
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that c…
Webaccess\/scada
after 9.0.1
MEDIUM 6.1
CVE-2021-24358
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before …
The Plus Addons For Elementor
4.1.10+
MEDIUM 6.1
CVE-2021-22903
The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certai…
Rails
6.1.3.2+
MEDIUM 5.4
CVE-2021-23393
This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation an…
Flask Unchained
0.9.0+
MEDIUM 6.1
CVE-2020-18268
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "…
Z Blogphp
after 1.5.2
MEDIUM 6.1
CVE-2021-31252EPSS 29%
An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can…
Bf 430 Firmware
No fix yet
MEDIUM 6.1
CVE-2021-1525
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malici…
Webex Meetings Online
3.0+
MEDIUM 6.1
CVE-2021-25640
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S…
Dubbo
2.6.9 / 2.7.9+
MEDIUM 6.1
CVE-2021-32645
Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirec…
Multi Tenant
5.7.2+
MEDIUM 6.1
CVE-2021-23387
The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerab…
Trailing Slash
2.0.1+
MEDIUM 6.1
CVE-2021-1358
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undes…
Finesse
after 12.6
MEDIUM 6.1
CVE-2021-29622EPSS 20%
Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seam…
Prometheus
2.26.1+
MEDIUM 6.1
CVE-2020-36365
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Ed…
Smartstorenet
4.1.0+
MEDIUM 6.1
CVE-2021-32618
The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained versi…
Flask Security
Mitigation only
MEDIUM 5.4
CVE-2021-23384
The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing…
Koa Remove Trailing Slashes
2.0.2+
MEDIUM 6.1
CVE-2021-24288
When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a l…
Acymailing
7.5.0+
MEDIUM 6.1
CVE-2021-27612
In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain …
Gui For Windows
Mitigation only
MEDIUM 6.1
CVE-2021-1397
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote…
Integrated Management Controller
3.2+
MEDIUM 6.1
CVE-2020-13662
Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitra…
Drupal
after 7.70