Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
CRITICAL 9.6 CVE-2026-53662 immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (X… Patch available Fix from $2,3002026-06-23 MEDIUM 6.1 CVE-2026-56326 Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validat… Nuxt 3.21.7 / 4.4.7+ Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-56697 Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass th… Nuxt 3.21.7 / 4.4.7+ Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-44889 WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerabl… Webob 1.8.10+ Fix from $1,6002026-06-22 MEDIUM 5.4 CVE-2026-41479 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can … Authlib 1.6.10+ Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-54276 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication resp… Aiohttp 3.14.1+ Fix from $1,6002026-06-22 MEDIUM 5.1 CVE-2026-12863 An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains. Mitigation only Fix from $1,6002026-06-22 HIGH 8.8 CVE-2026-47645 Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges ov… 365 Copilot Mitigation only Fix from $1,9502026-06-19 MEDIUM 5.4 CVE-2026-12622 The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from… Gridtime 3000 Firmware 1.2r0.0+ Fix from $1,6002026-06-19 HIGH 7.2 CVE-2026-48895 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an … Apisix 3.17.0+ Fix from $1,9502026-06-19 MEDIUM 6.1 CVE-2026-44915 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulner… Apisix 3.17.0+ Fix from $1,6002026-06-19 MEDIUM 6.1 CVE-2026-12049 Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form p… Pgadmin 4 9.16+ Fix from $1,6002026-06-19 HIGH 8.8 CVE-2026-55237 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 h… Mitigation only Fix from $1,9502026-06-18 MEDIUM 6.1 CVE-2025-32748 Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access… Powerflex Rack Release Certification Matrix 3.8.4.1 / 3.9.1.1+ Fix from $1,6002026-06-17 MEDIUM 5.1 CVE-2026-10839 Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the … Mitigation only Fix from $1,6002026-06-17 MEDIUM 5.1 CVE-2026-10837 Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that, w… Mitigation only Fix from $1,6002026-06-17 HIGH 7.5 CVE-2026-46955 Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected are 12.2.3-… Human Resources after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.0 CVE-2026-46894 Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affected are 12.… Isupplier Portal after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.2 CVE-2026-46806 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect… Webcenter Content Mitigation only Fix from $1,9502026-06-17 HIGH 8.0 CVE-2026-46796 Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected a… Webcenter Sites Mitigation only Fix from $1,9502026-06-17 HIGH 8.3 CVE-2026-35302 Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 a… Weblogic Server Mitigation only Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-35259 Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 a… Weblogic Server Mitigation only Fix from $1,9502026-06-17 HIGH 8.7 CVE-2026-35258 Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 a… Weblogic Server Mitigation only Fix from $1,9502026-06-17 MEDIUM 6.8 CVE-2026-53523 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRe… Mitigation only Fix from $1,6002026-06-12 MEDIUM 6.1 CVE-2026-50089 The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," wit… Iam\/sso Gateway No fix yet Fix from $1,6002026-06-12 MEDIUM 6.1 CVE-2026-46616 Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operati… Umbraco Cms 13.14.0 / 17.4.0+ Fix from $1,6002026-06-10 MEDIUM 6.5 CVE-2026-48856 Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards… Erlang\/inets 9.3.2.6 / 9.6.2.2+ Fix from $1,6002026-06-10 MEDIUM 6.1 CVE-2026-45566 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next… No fix yet Fix from $1,6002026-06-10 MEDIUM 6.1 CVE-2026-41706 Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be r… Spring Security 5.7.24 / 5.8.26+ Fix from $1,6002026-06-10 MEDIUM 6.1 CVE-2026-41008 Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a … Spring Security 1.5.7.1 / 7.0.5.1+ Fix from $1,6002026-06-10