Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2021-22984 On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before … Big Ip Advanced Web Application Firewall 11.6.5.2 / 12.1.5.2+ Fix from $1,6002021-02-12 MEDIUM 6.1 CVE-2021-22881EPSS 87% The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` header… Rails 6.0.3.5 / 6.1.2.1+ Fix from $1,6002021-02-11 MEDIUM 6.1 CVE-2020-13565 An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.… Openemr No fix yet Fix from $1,6002021-02-10 MEDIUM 6.1 CVE-2021-21476 SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a… Ui5 1.38.49 / 1.52.49+ Fix from $1,6002021-02-09 MEDIUM 6.1 CVE-2021-21478 SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. Web Dynpro Abap Mitigation only Fix from $1,6002021-02-09 MEDIUM 6.1 CVE-2020-22840EPSS 14% Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controll… B2evolution 6.11.6+ Fix from $1,6002021-02-09 MEDIUM 6.1 CVE-2021-25757 In JetBrains Hub before 2020.1.12629, an open redirect was possible. Hub 2020.1.12629+ Fix from $1,6002021-02-03 MEDIUM 6.1 CVE-2021-21291 OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to vali… Oauth2 Proxy 7.0.0+ Fix from $1,6002021-02-02 MEDIUM 5.4 CVE-2020-29537 Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users … Archer 6.6.0.8 / 6.7.0.8+ Fix from $1,6002021-01-29 MEDIUM 6.1 CVE-2020-1723 A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected ver… Mobile Application Platform Mitigation only Fix from $1,6002021-01-28 MEDIUM 6.1 CVE-2021-22873EPSS 70% Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scri… Revive Adserver 5.1.0+ Fix from $1,6002021-01-26 MEDIUM 5.4 CVE-2021-1218 A vulnerability in the web management interface of Cisco Smart Software Manager satellite could allow an authenticated, remote attacker to redirect a… Smart Software Manager On Prem after 5.0 Fix from $1,6002021-01-20 MEDIUM 6.1 CVE-2020-26979 When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then red… Firefox 84.0+ Fix from $1,6002021-01-07 MEDIUM 6.1 CVE-2020-29498 Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attacker could potentially exploit … Wyse Management Suite 3.1+ Fix from $1,6002021-01-04 HIGH 7.4 CVE-2020-25845 Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host,… Nhiservisignadapter Mitigation only Fix from $1,9502020-12-31 HIGH 7.4 CVE-2020-25846 The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to … Nhiservisignadapter Mitigation only Fix from $1,9502020-12-31 MEDIUM 6.1 CVE-2020-35678 Autobahn|Python before 20.12.3 allows redirect header injection. Autobahn 20.12.3+ Fix from $1,6002020-12-27 MEDIUM 6.1 CVE-2020-27729 In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an undisclosed link on the BIG-IP… Big Ip Access Policy Manager 13.1.3.5 / 14.1.3.1+ Fix from $1,6002020-12-24 MEDIUM 6.1 CVE-2020-4840 IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to v… Security Secret Server Patch available Fix from $1,6002020-12-21 MEDIUM 6.1 CVE-2020-26275 The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, Jupyte… Jupyter Server 1.1.1+ Fix from $1,6002020-12-21 MEDIUM 6.1 CVE-2020-25901EPSS 5% Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host head… Spiceworks No fix yet Fix from $1,6002020-12-18 MEDIUM 6.1 CVE-2020-4849 IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse t… Tivoli Netcool\/impact after 7.1.0.19 Fix from $1,6002020-12-15 MEDIUM 6.1 CVE-2020-26836 SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability,… Solution Manager No fix yet Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-29565 An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of v… Debian Linux 15.3.2 / 16.2.1+ Fix from $1,6002020-12-04 MEDIUM 6.1 CVE-2020-27816 The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the ori… Kibana after 4.7 Fix from $1,6002020-12-02 MEDIUM 5.4 CVE-2020-26232 Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server could redirect the browser to … Jupyter Server 1.0.6+ Fix from $1,6002020-11-24 MEDIUM 6.1 CVE-2020-28726 Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php. Seeddms Patch available Fix from $1,6002020-11-24 MEDIUM 6.1 CVE-2020-15300 SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document. Suitecrm after 7.11.13 Fix from $1,6002020-11-18 MEDIUM 6.1 CVE-2020-26215 Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser … Debian Linux 6.1.5+ Fix from $1,6002020-11-18 MEDIUM 6.1 CVE-2020-28724 Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL. Werkzeug 0.11.6+ Fix from $1,6002020-11-18