Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2019-15820
The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication.
Login Or Logout Menu Item
1.2.0+
MEDIUM 6.1
CVE-2019-15771
The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
Components For Wp Bakery Page Builder
6.0+
MEDIUM 6.1
CVE-2019-15772
The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
Donations
1.4+
MEDIUM 6.1
CVE-2019-15773
The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
Travel Management
1.7+
MEDIUM 6.1
CVE-2019-15774
The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
Booking
2.5+
MEDIUM 6.1
CVE-2019-15775
The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
Learning Courses
4.8+
MEDIUM 6.1
CVE-2019-15776
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
Simple 301 Redirects Addon Bulk Uploader
1.2.5+
MEDIUM 6.1
CVE-2016-6154
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
Fireware
after 11.11
HIGH 8.8
CVE-2019-10751
All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with sup…
Httpie
No fix yet
MEDIUM 6.1
CVE-2019-11589
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.…
Jira Server
7.13.6 / 8.2.3+
MEDIUM 6.1
CVE-2019-13422
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious…
Search Guard
5.6.8-7 / 6.2.3-12+
MEDIUM 6.1
CVE-2019-11585
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows r…
Jira
7.13.6 / 8.2.3+
MEDIUM 6.1
CVE-2019-1954
A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redi…
Webex Meetings Server
4.0+
MEDIUM 6.1
CVE-2019-10372
An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users…
Gitlab Oauth
after 1.4
MEDIUM 6.1
CVE-2016-10769
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
Cpanel
11.54.0.33 / 56.0.39+
MEDIUM 5.0
CVE-2017-18441
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
Cpanel
56.0.49 / 58.0.49+
HIGH 7.4
CVE-2017-18414
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
Cpanel
56.0.52 / 60.0.48+
HIGH 8.1
CVE-2019-9140
When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascrip…
Happypoint
Mitigation only
MEDIUM 6.1
CVE-2018-20929
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
Cpanel
62.0.42 / 68.0.33+
MEDIUM 6.1
CVE-2018-20867
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
Cpanel
76.0.8+
MEDIUM 6.1
CVE-2019-1020016
ASH-AIO before 2.0.0.3 allows an open redirect.
Ash Aio
No fix yet
MEDIUM 6.1
CVE-2019-1943EPSS 11%
A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attack…
Sg200 50 Firmware
Mitigation only
MEDIUM 6.1
CVE-2019-1010290
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "n…
Bable\
after 0.4.1
MEDIUM 6.1
CVE-2019-1075
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
Asp.net Core
Patch available
MEDIUM 6.1
CVE-2018-12621
An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
Eventum
Mitigation only
MEDIUM 6.1
CVE-2019-5965
Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing at…
Joruri Mail
after 2.1.4
MEDIUM 6.1
CVE-2019-5969
Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks …
Growi
after 3.4.6
MEDIUM 6.1
CVE-2019-10721
BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Securit…
Blogengine.net
Patch available
MEDIUM 6.1
CVE-2019-13175
Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addit…
Read The Docs
3.5.1+
MEDIUM 6.1
CVE-2019-7275EPSS 9%
Optergy Proton/Enterprise devices allow Open Redirect.
Enterprise
after 2.3.0a