Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2019-3877 A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by a… Mod Auth Mellon 0.14.2+ Fix from $1,6002019-03-27 MEDIUM 6.1 CVE-2019-3850 A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (… Moodle 3.1.17 / 3.4.8+ Fix from $1,6002019-03-26 MEDIUM 5.4 CVE-2019-4035 IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, the… Content Navigator Mitigation only Fix from $1,6002019-03-22 MEDIUM 6.1 CVE-2019-9915 GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter. Getsimplecms Mitigation only Fix from $1,6002019-03-22 MEDIUM 6.1 CVE-2019-9837 Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri fi… Openid Connect 1.5.4+ Fix from $1,6002019-03-21 MEDIUM 6.1 CVE-2019-7416 XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnera… Documentum Webtop No fix yet Fix from $1,6002019-03-21 MEDIUM 6.1 CVE-2018-17422 dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp… Dotcms 5.0.2+ Fix from $1,6002019-03-07 MEDIUM 6.5 CVE-2019-3778EPSS 15% Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported ve… Spring Security Oauth 2.0.17 / 2.1.4+ Fix from $1,6002019-03-07 MEDIUM 5.5 CVE-2019-0540EPSS 13% A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file,… Excel Viewer Patch available Fix from $1,6002019-03-05 MEDIUM 6.1 CVE-2018-1875 IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect … Infosphere Information Governance Catalog Mitigation only Fix from $1,6002019-03-05 MEDIUM 6.1 CVE-2018-1939 IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a s… Cloud Private Mitigation only Fix from $1,6002019-03-05 MEDIUM 6.1 CVE-2018-19106 Avi Vantage before 17.2.13 uses an invalid URL encoding during a redirect operation, aka AV-33959. Avi Vantage 17.2.13+ Fix from $1,6002019-02-20 MEDIUM 6.1 CVE-2016-10742 Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the req… Debian Linux after 3.4.3 Fix from $1,6002019-02-17 MEDIUM 6.1 CVE-2019-5915 Open redirect vulnerability in OpenAM (Open Source Edition) 13.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishin… Openam after 13.0.0-137 Fix from $1,6002019-02-13 MEDIUM 6.1 CVE-2019-3912 An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticate… Labkey Server 18.3.0-61806.763+ Fix from $1,6002019-01-30 MEDIUM 6.1 CVE-2019-6780 The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and… Wise Chat 2.7+ Fix from $1,6002019-01-24 MEDIUM 6.1 CVE-2018-16191 Open redirect vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3.0.4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-C… Ec Cube after 3.0.16 Fix from $1,6002019-01-09 MEDIUM 6.1 CVE-2018-16174 Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishin… Learnpress 3.1.0+ Fix from $1,6002019-01-09 MEDIUM 6.1 CVE-2018-0688 Open redirect vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware version… Ds 570w Firmware 2017-06-12 / 2017-06-19+ Fix from $1,6002019-01-09 MEDIUM 5.4 CVE-2018-15798 Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could co… Concourse 4.2.2+ Fix from $1,6002018-12-19 MEDIUM 6.1 CVE-2018-19790 An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4… Symfony 2.7.50 / 2.8.49+ Fix from $1,6002018-12-18 MEDIUM 6.1 CVE-2018-7797 A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME)… Ecostruxure Energy Expert Mitigation only Fix from $1,6002018-12-17 MEDIUM 6.1 CVE-2018-7804 A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where … Modicom M340 Firmware Mitigation only Fix from $1,6002018-12-17 HIGH 8.1 CVE-2018-13813 A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15"… Simatic Hmi Comfort Panels Firmware after 15.0 Fix from $1,9502018-12-13 MEDIUM 6.1 CVE-2018-1654 IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phishing attacks, using an open re… Curam Social Program Management after 7.0.3.0 Fix from $1,6002018-12-11 MEDIUM 6.1 CVE-2018-19796 An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-p… Ninja Forms 3.3.19.1+ Fix from $1,6002018-12-03 MEDIUM 6.1 CVE-2018-11067 Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrate… Vsphere Data Protection Patch available Fix from $1,6002018-11-26 MEDIUM 6.1 CVE-2018-17948 An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3. Access Manager 4.4+ Fix from $1,6002018-11-20 MEDIUM 6.1 CVE-2018-2476 Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site. Netweaver Mitigation only Fix from $1,6002018-11-13 MEDIUM 6.1 CVE-2018-14658 A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.Red… Keycloak Mitigation only Fix from $1,6002018-11-13