Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2020-26219
touchbase.ai before version 2.0 is vulnerable to Open Redirect. Impacts can be many, and vary from theft of information and credentials, to the redir…
Touchbase.ai
2.0+
MEDIUM 6.1
CVE-2020-26161
In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.
Octopus Deploy
after 2020.4.2
MEDIUM 6.1
CVE-2020-3558
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote atta…
Secure Firewall Management Center
after 6.5.0.4
MEDIUM 6.1
CVE-2020-6365
SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2020-24551
IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to redirect to any malicious site a…
Mmc\+
Mitigation only
MEDIUM 6.1
CVE-2020-15241
TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripti…
Fluid Engine
2.0.5 / 2.1.4+
MEDIUM 6.1
CVE-2020-15242
Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to all…
Next.js
9.5.4+
MEDIUM 6.1
CVE-2020-15677
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the …
Firefox
78.3 / 81.0+
MEDIUM 6.1
CVE-2019-15974
A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user t…
Managed Services Accelerator
3.7.0+
HIGH 8.2
CVE-2020-4409
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a vic…
Control Desk
7.6.1.2+
MEDIUM 6.1
CVE-2020-5627
Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As…
Yodobashi
after 1.8.7
HIGH 7.5
CVE-2020-24554
The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote a…
Liferay Portal
7.3.3+
MEDIUM 6.1
CVE-2020-5623
NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access a…
Nitori
after 6.0.4
MEDIUM 6.1
CVE-2020-24598
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
Joomla\!
3.9.21+
MEDIUM 6.1
CVE-2020-5541
Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attack…
Cybermail
Mitigation only
MEDIUM 5.3
CVE-2020-10775
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary we…
Ovirt Engine
after 4.4
MEDIUM 6.1
CVE-2020-4598
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim…
Security Guardium Insights
Mitigation only
MEDIUM 6.1
CVE-2020-4653
IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit …
Planning Analytics
Patch available
MEDIUM 6.8
CVE-2020-8559EPSS 6%
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect o…
Kubernetes
1.16.13 / 1.17.9+
MEDIUM 6.1
CVE-2019-12783
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after …
Impact 360
No fix yet
MEDIUM 6.1
CVE-2019-20901
The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a diffe…
Jira
8.5.2+
MEDIUM 6.1
CVE-2020-5607
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing at…
Shirasagi
after 1.13.1
MEDIUM 6.1
CVE-2020-11882
The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. The purpose of this activity is…
O2 Business
No fix yet
MEDIUM 5.4
CVE-2020-4037
In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to …
Oauth2 Proxy
6.0.0+
MEDIUM 6.1
CVE-2017-18897
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action …
Mattermost Server
4.0.5 / 4.1.1+
MEDIUM 6.1
CVE-2017-18891
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
Mattermost Server
4.0.5 / 4.1.1+
MEDIUM 6.1
CVE-2020-14454
An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is…
Mattermost Desktop
4.4.0+
MEDIUM 6.1
CVE-2020-14446
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.
Identity Server
after 5.10.0
MEDIUM 6.1
CVE-2020-3337
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The …
Umbrella
Mitigation only
MEDIUM 5.7
CVE-2020-4048
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading …
WordPress
3.7.34 / 3.8.34+