Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2019-3877
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by a…
Mod Auth Mellon
0.14.2+
MEDIUM 6.1
CVE-2019-3850
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (…
Moodle
3.1.17 / 3.4.8+
MEDIUM 5.4
CVE-2019-4035
IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, the…
Content Navigator
Mitigation only
MEDIUM 6.1
CVE-2019-9915
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
Getsimplecms
Mitigation only
MEDIUM 6.1
CVE-2019-9837
Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri fi…
Openid Connect
1.5.4+
MEDIUM 6.1
CVE-2019-7416
XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnera…
Documentum Webtop
No fix yet
MEDIUM 6.1
CVE-2018-17422
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp…
Dotcms
5.0.2+
MEDIUM 6.5
CVE-2019-3778EPSS 15%
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported ve…
Spring Security Oauth
2.0.17 / 2.1.4+
MEDIUM 5.5
CVE-2019-0540EPSS 13%
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file,…
Excel Viewer
Patch available
MEDIUM 6.1
CVE-2018-1875
IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect …
Infosphere Information Governance Catalog
Mitigation only
MEDIUM 6.1
CVE-2018-1939
IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a s…
Cloud Private
Mitigation only
MEDIUM 6.1
CVE-2018-19106
Avi Vantage before 17.2.13 uses an invalid URL encoding during a redirect operation, aka AV-33959.
Avi Vantage
17.2.13+
MEDIUM 6.1
CVE-2016-10742
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the req…
Debian Linux
after 3.4.3
MEDIUM 6.1
CVE-2019-5915
Open redirect vulnerability in OpenAM (Open Source Edition) 13.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishin…
Openam
after 13.0.0-137
MEDIUM 6.1
CVE-2019-3912
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticate…
Labkey Server
18.3.0-61806.763+
MEDIUM 6.1
CVE-2019-6780
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and…
Wise Chat
2.7+
MEDIUM 6.1
CVE-2018-16191
Open redirect vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3.0.4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-C…
Ec Cube
after 3.0.16
MEDIUM 6.1
CVE-2018-16174
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishin…
Learnpress
3.1.0+
MEDIUM 6.1
CVE-2018-0688
Open redirect vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware version…
Ds 570w Firmware
2017-06-12 / 2017-06-19+
MEDIUM 5.4
CVE-2018-15798
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could co…
Concourse
4.2.2+
MEDIUM 6.1
CVE-2018-19790
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4…
Symfony
2.7.50 / 2.8.49+
MEDIUM 6.1
CVE-2018-7797
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME)…
Ecostruxure Energy Expert
Mitigation only
MEDIUM 6.1
CVE-2018-7804
A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where …
Modicom M340 Firmware
Mitigation only
HIGH 8.1
CVE-2018-13813
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15"…
Simatic Hmi Comfort Panels Firmware
after 15.0
MEDIUM 6.1
CVE-2018-1654
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phishing attacks, using an open re…
Curam Social Program Management
after 7.0.3.0
MEDIUM 6.1
CVE-2018-19796
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-p…
Ninja Forms
3.3.19.1+
MEDIUM 6.1
CVE-2018-11067
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrate…
Vsphere Data Protection
Patch available
MEDIUM 6.1
CVE-2018-17948
An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.
Access Manager
4.4+
MEDIUM 6.1
CVE-2018-2476
Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.
Netweaver
Mitigation only
MEDIUM 6.1
CVE-2018-14658
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.Red…
Keycloak
Mitigation only