Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2020-23015 An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user t… Opnsense after 20.1.5 Fix from $1,6002021-05-03 MEDIUM 6.1 CVE-2021-29137 A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches f… Airwave 8.2.12.1+ Fix from $1,6002021-04-29 MEDIUM 6.1 CVE-2021-31879 GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007. Wget after 1.21.1 Fix from $1,6002021-04-29 MEDIUM 6.1 CVE-2020-21998 In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect user… Homeautomation No fix yet Fix from $1,6002021-04-27 MEDIUM 6.1 CVE-2021-28125EPSS 64% Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open re… Superset after 1.0.1 Fix from $1,6002021-04-27 MEDIUM 5.4 CVE-2021-29456 Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on (SSO) for your applications v… Authelia 4.28.0+ Fix from $1,6002021-04-21 MEDIUM 6.3 CVE-2021-21392 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging… Fedora 1.28.0+ Fix from $1,6002021-04-12 MEDIUM 6.1 CVE-2021-24210 There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and … Phastpress 1.111+ Fix from $1,6002021-04-05 MEDIUM 6.1 CVE-2021-24165 In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the u… Ninja Forms 3.4.34+ Fix from $1,6002021-04-05 MEDIUM 6.1 CVE-2020-9995 An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Server 5.11. Processin… Macos Server 5.11+ Fix from $1,6002021-04-02 MEDIUM 6.1 CVE-2021-29651 Pomerium before 0.13.4 has an Open Redirect (issue 1 of 2). Pomerium 0.13.4+ Fix from $1,6002021-04-02 MEDIUM 6.1 CVE-2021-29652 Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process Pomerium after 0.13.3 Fix from $1,6002021-04-02 MEDIUM 6.1 CVE-2020-24550 An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect paramet… Find 13.2.7+ Fix from $1,6002021-03-31 MEDIUM 5.4 CVE-2021-27352 An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login. Ilch Cms No fix yet Fix from $1,6002021-03-29 MEDIUM 6.1 CVE-2021-1629 Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users. Tableau Server 2019.4.18 / 2020.1.15+ Fix from $1,6002021-03-26 MEDIUM 6.3 CVE-2021-23888 Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user… Epolicy Orchestrator 5.10.0+ Fix from $1,6002021-03-26 MEDIUM 6.1 CVE-2020-12483 The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructe… Appstore 8.12.0.0+ Fix from $1,6002021-03-23 MEDIUM 5.4 CVE-2021-21377 OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL af… Omero.web 5.9.0+ Fix from $1,6002021-03-23 MEDIUM 6.1 CVE-2021-21338 TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been… TYPO3 6.2.57 / 7.6.51+ Fix from $1,6002021-03-23 MEDIUM 6.1 CVE-2019-14830 A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint conta… Moodle after 3.7.1 Fix from $1,6002021-03-19 MEDIUM 6.1 CVE-2019-14831 A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained a… Moodle after 3.7.1 Fix from $1,6002021-03-19 MEDIUM 6.1 CVE-2021-21491 SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attack… Netweaver Application Server Java Mitigation only Fix from $1,6002021-03-10 MEDIUM 6.1 CVE-2020-28150 I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user s… I Net Clear Reports No fix yet Fix from $1,6002021-03-09 MEDIUM 6.1 CVE-2021-21337EPSS 8% Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t… Products.pluggableauthservice 2.6.1+ Fix from $1,6002021-03-08 MEDIUM 6.1 CVE-2021-21354 Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release p… Pollbot 1.4.4+ Fix from $1,6002021-03-08 MEDIUM 6.1 CVE-2021-21273 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging… Fedora 1.25.0+ Fix from $1,6002021-02-26 MEDIUM 6.1 CVE-2021-21330 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerabili… Debian Linux 3.7.4+ Fix from $1,6002021-02-26 MEDIUM 6.1 CVE-2021-3189 The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring. Slashify No fix yet Fix from $1,6002021-02-19 MEDIUM 6.1 CVE-2021-27404 Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header. Askey Rtf8115vw Firmware No fix yet Fix from $1,6002021-02-19 MEDIUM 6.1 CVE-2020-35560 An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php. Mbconnect24 after 2.6.2 Fix from $1,6002021-02-16