Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.6
CVE-2026-53662
immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (X…
Patch available
MEDIUM 6.1
CVE-2026-56326
Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validat…
Nuxt
3.21.7 / 4.4.7+
MEDIUM 6.1
CVE-2026-56697
Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass th…
Nuxt
3.21.7 / 4.4.7+
MEDIUM 6.1
CVE-2026-44889
WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerabl…
Webob
1.8.10+
MEDIUM 5.4
CVE-2026-41479
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can …
Authlib
1.6.10+
MEDIUM 6.1
CVE-2026-54276
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication resp…
Aiohttp
3.14.1+
MEDIUM 5.1
CVE-2026-12863
An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.
Mitigation only
HIGH 8.8
CVE-2026-47645
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges ov…
365 Copilot
Mitigation only
MEDIUM 5.4
CVE-2026-12622
The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission.
This issue affects GridTime 3000: from…
Gridtime 3000 Firmware
1.2r0.0+
HIGH 7.2
CVE-2026-48895
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The attacker could manipulate some client headers to perform an …
Apisix
3.17.0+
MEDIUM 6.1
CVE-2026-44915
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The default configuration of cas-auth in Apache APISIX is vulner…
Apisix
3.17.0+
MEDIUM 6.1
CVE-2026-12049
Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form p…
Pgadmin 4
9.16+
HIGH 8.8
CVE-2026-55237
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 h…
Mitigation only
MEDIUM 6.1
CVE-2025-32748
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access…
Powerflex Rack Release Certification Matrix
3.8.4.1 / 3.9.1.1+
MEDIUM 5.1
CVE-2026-10839
Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the …
Mitigation only
MEDIUM 5.1
CVE-2026-10837
Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that, w…
Mitigation only
HIGH 7.5
CVE-2026-46955
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected are 12.2.3-…
Human Resources
after 12.2.15
HIGH 8.0
CVE-2026-46894
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affected are 12.…
Isupplier Portal
after 12.2.15
HIGH 8.2
CVE-2026-46806
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect…
Webcenter Content
Mitigation only
HIGH 8.0
CVE-2026-46796
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected a…
Webcenter Sites
Mitigation only
HIGH 8.3
CVE-2026-35302
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 a…
Weblogic Server
Mitigation only
HIGH 8.8
CVE-2026-35259
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 a…
Weblogic Server
Mitigation only
HIGH 8.7
CVE-2026-35258
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 a…
Weblogic Server
Mitigation only
MEDIUM 6.8
CVE-2026-53523
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRe…
Mitigation only
MEDIUM 6.1
CVE-2026-50089
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," wit…
Iam\/sso Gateway
No fix yet
MEDIUM 6.1
CVE-2026-46616
Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operati…
Umbraco Cms
13.14.0 / 17.4.0+
MEDIUM 6.5
CVE-2026-48856
Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data.
The httpc client forwards…
Erlang\/inets
9.3.2.6 / 9.6.2.2+
MEDIUM 6.1
CVE-2026-45566
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next…
No fix yet
MEDIUM 6.1
CVE-2026-41706
Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be r…
Spring Security
5.7.24 / 5.8.26+
MEDIUM 6.1
CVE-2026-41008
Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a …
Spring Security
1.5.7.1 / 7.0.5.1+