Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2020-6266
SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation…
Fiori
Mitigation only
MEDIUM 6.1
CVE-2020-1323
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link…
Sharepoint Enterprise Server
Patch available
MEDIUM 6.1
CVE-2020-1220
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromi…
Edge
Patch available
MEDIUM 6.1
CVE-2020-10959
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML cont…
Mediawiki
1.35+
MEDIUM 6.1
CVE-2020-13486
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
Knock Knock
1.2.8+
MEDIUM 6.1
CVE-2020-13121
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
Submitty
after 20.04.01
MEDIUM 6.1
CVE-2020-5409
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could co…
Concourse
5.2.8 / 5.5.10+
MEDIUM 6.1
CVE-2020-1997
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection …
Pan Os
7.1.26 / 8.0.14+
MEDIUM 6.1
CVE-2020-12699
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
Direct Mail
after 5.2.3
MEDIUM 6.1
CVE-2020-11053
In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated u…
Oauth2 Proxy
5.1.1+
MEDIUM 6.1
CVE-2020-3311
A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect …
Secure Firewall Management Center
6.3.0+
MEDIUM 6.1
CVE-2020-3178
Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthen…
Content Security Management Appliance
13.6.0+
MEDIUM 6.1
CVE-2020-12666
macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.
Fedora
1.3.7+
MEDIUM 6.1
CVE-2020-11034EPSS 8%
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is f…
Glpi
9.4.6+
MEDIUM 6.1
CVE-2020-5337
RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit …
Archer
6.7.0.1+
MEDIUM 6.1
CVE-2019-4209
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
Connections
Patch available
MEDIUM 6.1
CVE-2020-12283
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/…
Sourcegraph
3.15.1+
MEDIUM 6.1
CVE-2020-5270
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from th…
Prestashop
1.7.6.5+
MEDIUM 6.1
CVE-2020-5732
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user…
Openmrs
after 2.9.0
MEDIUM 6.1
CVE-2020-5733
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated use…
Openmrs
after 2.9.0
MEDIUM 6.1
CVE-2020-11665
CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect…
Ca Api Developer Portal
after 4.3.1
MEDIUM 6.1
CVE-2020-11663
CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.
Ca Api Developer Portal
after 4.3.1
MEDIUM 6.1
CVE-2020-11664
CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect …
Ca Api Developer Portal
after 4.3.1
MEDIUM 6.1
CVE-2020-3954
Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
Vrealize Log Insight
8.1.0+
MEDIUM 6.1
CVE-2020-6211
SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to …
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.1
CVE-2020-6215
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker…
Netweaver As Abap Business Server Pages
No fix yet
MEDIUM 6.1
CVE-2020-6223
The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to incl…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.1
CVE-2020-8430
Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the atta…
Stormshield Network Security
after 4.0.1
MEDIUM 6.1
CVE-2020-11611
An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOri…
Cross Domain Local Storage
after 2.0.5
MEDIUM 6.1
CVE-2020-11515
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site…
Seo
after 1.0.40.2