Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2019-13038 mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target U… Mod Auth Mellon after 0.14.2 Fix from $1,6002019-06-29 MEDIUM 5.4 CVE-2019-5823 Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restriction… Chrome 74.0.3729.108+ Fix from $1,6002019-06-27 MEDIUM 6.1 CVE-2019-10133 A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricte… Moodle after 3.6.3 Fix from $1,6002019-06-26 MEDIUM 6.8 CVE-2019-4153 IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi… Security Access Manager after 9.0.6 Fix from $1,6002019-06-25 MEDIUM 6.1 CVE-2017-14394 OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly valida… Access Management after 13.5.1 Fix from $1,6002019-06-19 MEDIUM 5.4 CVE-2019-11269EPSS 9% Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported vers… Spring Security Oauth 2.0.18 / 2.1.5+ Fix from $1,6002019-06-12 MEDIUM 6.1 CVE-2019-3477 Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect. Solutions Business Manager 11.4.2+ Fix from $1,6002019-06-07 MEDIUM 6.1 CVE-2019-4201 IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.… Jazz For Service Management after 1.1.3.2 Fix from $1,6002019-06-06 MEDIUM 6.1 CVE-2018-13384 A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially… Fortios 6.0.5+ Fix from $1,6002019-06-04 CRITICAL 9.3 CVE-2019-6741 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security … Galaxy S9 Firmware 2019-01+ Fix from $2,3002019-06-03 MEDIUM 5.4 CVE-2017-5871 Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote). Odoo No fix yet Fix from $1,6002019-05-22 MEDIUM 6.1 CVE-2019-5946 Open redirect vulnerability in Cybozu Garoon 4.2.4 to 4.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at… Garoon after 4.10.1 Fix from $1,6002019-05-17 HIGH 7.5 CVE-2019-6781 An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 1… GitLab 11.5.10 / 11.6.8+ Fix from $1,9502019-05-17 MEDIUM 6.1 CVE-2019-10117 An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A red… GitLab 11.7.8 / 11.8.4+ Fix from $1,6002019-05-16 MEDIUM 6.1 CVE-2019-8951 An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a … Divar Ip 2000 Firmware 3.62.0019 / 3.70.0056+ Fix from $1,6002019-05-13 MEDIUM 6.1 CVE-2018-12300 Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'sta… Nas Os No fix yet Fix from $1,6002019-05-13 MEDIUM 5.4 CVE-2019-5433 A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL th… Revive Adserver 4.2.0+ Fix from $1,6002019-05-06 MEDIUM 6.1 CVE-2018-14931 An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?I… Intellect Core Banking No fix yet Fix from $1,6002019-04-30 MEDIUM 6.1 CVE-2019-4166 IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a speciall… Storediq after 7.6.0.18 Fix from $1,6002019-04-30 MEDIUM 6.1 CVE-2019-3788 Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured w… Uaa Release 71.0+ Fix from $1,6002019-04-25 MEDIUM 6.1 CVE-2019-10955 In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earli… Micrologix 1400 A Firmware after 30.014 Fix from $1,6002019-04-25 MEDIUM 6.1 CVE-2019-4092 IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victi… Content Navigator Mitigation only Fix from $1,6002019-04-25 MEDIUM 6.1 CVE-2019-8995 The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distributi… Activematrix Bpm after 4.2.0 Fix from $1,6002019-04-24 MEDIUM 6.1 CVE-2018-20698 The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set. Search Guard 6.3.0-16+ Fix from $1,6002019-04-09 MEDIUM 6.1 CVE-2019-11016 Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect. Elgg 1.12.18 / 2.3.11+ Fix from $1,6002019-04-08 MEDIUM 6.1 CVE-2019-10856 In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255. Notebook 5.7.8+ Fix from $1,6002019-04-04 MEDIUM 6.1 CVE-2018-15180 qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter. Qtest Manager No fix yet Fix from $1,6002019-04-02 MEDIUM 6.1 CVE-2018-8913 Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted U… Web Station 2.1.3-0139+ Fix from $1,6002019-04-01 MEDIUM 6.1 CVE-2017-18109 The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect… Crowd 3.0.2+ Fix from $1,6002019-03-29 MEDIUM 6.1 CVE-2019-10255 An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allow… Jupyterhub 0.9.5 / 5.7.7+ Fix from $1,6002019-03-28