Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2019-13038
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target U…
Mod Auth Mellon
after 0.14.2
MEDIUM 5.4
CVE-2019-5823
Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restriction…
Chrome
74.0.3729.108+
MEDIUM 6.1
CVE-2019-10133
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricte…
Moodle
after 3.6.3
MEDIUM 6.8
CVE-2019-4153
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi…
Security Access Manager
after 9.0.6
MEDIUM 6.1
CVE-2017-14394
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly valida…
Access Management
after 13.5.1
MEDIUM 5.4
CVE-2019-11269EPSS 9%
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported vers…
Spring Security Oauth
2.0.18 / 2.1.5+
MEDIUM 6.1
CVE-2019-3477
Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.
Solutions Business Manager
11.4.2+
MEDIUM 6.1
CVE-2019-4201
IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.…
Jazz For Service Management
after 1.1.3.2
MEDIUM 6.1
CVE-2018-13384
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially…
Fortios
6.0.5+
CRITICAL 9.3
CVE-2019-6741
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security …
Galaxy S9 Firmware
2019-01+
MEDIUM 5.4
CVE-2017-5871
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
Odoo
No fix yet
MEDIUM 6.1
CVE-2019-5946
Open redirect vulnerability in Cybozu Garoon 4.2.4 to 4.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at…
Garoon
after 4.10.1
HIGH 7.5
CVE-2019-6781
An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 1…
GitLab
11.5.10 / 11.6.8+
MEDIUM 6.1
CVE-2019-10117
An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A red…
GitLab
11.7.8 / 11.8.4+
MEDIUM 6.1
CVE-2019-8951
An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a …
Divar Ip 2000 Firmware
3.62.0019 / 3.70.0056+
MEDIUM 6.1
CVE-2018-12300
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'sta…
Nas Os
No fix yet
MEDIUM 5.4
CVE-2019-5433
A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL th…
Revive Adserver
4.2.0+
MEDIUM 6.1
CVE-2018-14931
An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?I…
Intellect Core Banking
No fix yet
MEDIUM 6.1
CVE-2019-4166
IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a speciall…
Storediq
after 7.6.0.18
MEDIUM 6.1
CVE-2019-3788
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured w…
Uaa Release
71.0+
MEDIUM 6.1
CVE-2019-10955
In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earli…
Micrologix 1400 A Firmware
after 30.014
MEDIUM 6.1
CVE-2019-4092
IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victi…
Content Navigator
Mitigation only
MEDIUM 6.1
CVE-2019-8995
The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distributi…
Activematrix Bpm
after 4.2.0
MEDIUM 6.1
CVE-2018-20698
The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
Search Guard
6.3.0-16+
MEDIUM 6.1
CVE-2019-11016
Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.
Elgg
1.12.18 / 2.3.11+
MEDIUM 6.1
CVE-2019-10856
In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.
Notebook
5.7.8+
MEDIUM 6.1
CVE-2018-15180
qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter.
Qtest Manager
No fix yet
MEDIUM 6.1
CVE-2018-8913
Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted U…
Web Station
2.1.3-0139+
MEDIUM 6.1
CVE-2017-18109
The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect…
Crowd
3.0.2+
MEDIUM 6.1
CVE-2019-10255
An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allow…
Jupyterhub
0.9.5 / 5.7.7+