Vulnerability index

Browse CVEs

1,444 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 5.4 CVE-2020-6266 SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation… Fiori Mitigation only Fix from $1,6002020-06-10 MEDIUM 6.1 CVE-2020-1323 An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link… Sharepoint Enterprise Server Patch available Fix from $1,6002020-06-09 MEDIUM 6.1 CVE-2020-1220 A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromi… Edge Patch available Fix from $1,6002020-06-09 MEDIUM 6.1 CVE-2020-10959 resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML cont… Mediawiki 1.35+ Fix from $1,6002020-06-02 MEDIUM 6.1 CVE-2020-13486 The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection. Knock Knock 1.2.8+ Fix from $1,6002020-05-25 MEDIUM 6.1 CVE-2020-13121 Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt. Submitty after 20.04.01 Fix from $1,6002020-05-16 MEDIUM 6.1 CVE-2020-5409 Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could co… Concourse 5.2.8 / 5.5.10+ Fix from $1,6002020-05-14 MEDIUM 6.1 CVE-2020-1997 An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection … Pan Os 7.1.26 / 8.0.14+ Fix from $1,6002020-05-13 MEDIUM 6.1 CVE-2020-12699 The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl. Direct Mail after 5.2.3 Fix from $1,6002020-05-13 MEDIUM 6.1 CVE-2020-11053 In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated u… Oauth2 Proxy 5.1.1+ Fix from $1,6002020-05-07 MEDIUM 6.1 CVE-2020-3311 A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect … Secure Firewall Management Center 6.3.0+ Fix from $1,6002020-05-06 MEDIUM 6.1 CVE-2020-3178 Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthen… Content Security Management Appliance 13.6.0+ Fix from $1,6002020-05-06 MEDIUM 6.1 CVE-2020-12666 macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL. Fedora 1.3.7+ Fix from $1,6002020-05-05 MEDIUM 6.1 CVE-2020-11034EPSS 8% In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is f… Glpi 9.4.6+ Fix from $1,6002020-05-05 MEDIUM 6.1 CVE-2020-5337 RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit … Archer 6.7.0.1+ Fix from $1,6002020-05-04 MEDIUM 6.1 CVE-2019-4209 HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks. Connections Patch available Fix from $1,6002020-05-01 MEDIUM 6.1 CVE-2020-12283 Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/… Sourcegraph 3.15.1+ Fix from $1,6002020-04-30 MEDIUM 6.1 CVE-2020-5270 In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from th… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5732 In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user… Openmrs after 2.9.0 Fix from $1,6002020-04-17 MEDIUM 6.1 CVE-2020-5733 In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated use… Openmrs after 2.9.0 Fix from $1,6002020-04-17 MEDIUM 6.1 CVE-2020-11665 CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect… Ca Api Developer Portal after 4.3.1 Fix from $1,6002020-04-15 MEDIUM 6.1 CVE-2020-11663 CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks. Ca Api Developer Portal after 4.3.1 Fix from $1,6002020-04-15 MEDIUM 6.1 CVE-2020-11664 CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect … Ca Api Developer Portal after 4.3.1 Fix from $1,6002020-04-15 MEDIUM 6.1 CVE-2020-3954 Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. Vrealize Log Insight 8.1.0+ Fix from $1,6002020-04-15 MEDIUM 6.1 CVE-2020-6211 SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-04-14 MEDIUM 6.1 CVE-2020-6215 SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker… Netweaver As Abap Business Server Pages No fix yet Fix from $1,6002020-04-14 MEDIUM 6.1 CVE-2020-6223 The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to incl… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-04-14 MEDIUM 6.1 CVE-2020-8430 Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the atta… Stormshield Network Security after 4.0.1 Fix from $1,6002020-04-13 MEDIUM 6.1 CVE-2020-11611 An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOri… Cross Domain Local Storage after 2.0.5 Fix from $1,6002020-04-07 MEDIUM 6.1 CVE-2020-11515 The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site… Seo after 1.0.40.2 Fix from $1,6002020-04-07