Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2018-11408
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and…
Symfony
2.7.48 / 2.8.41+
MEDIUM 6.1
CVE-2017-16652
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSucce…
Symfony
2.7.38 / 2.8.31+
MEDIUM 6.1
CVE-2017-5389
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests…
Firefox
51.0+
HIGH 8.8
CVE-2016-9078
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in…
Firefox
Patch available
MEDIUM 6.1
CVE-2017-16224
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domai…
St
after 1.2.1
MEDIUM 6.1
CVE-2017-1748
IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to…
Connections
Patch available
MEDIUM 6.1
CVE-2018-3743
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
Hekto
after 0.2.3
MEDIUM 6.1
CVE-2018-10651
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Xenmobile Server
Mitigation only
MEDIUM 6.1
CVE-2015-8094
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac…
Hue
3.10.0+
MEDIUM 6.1
CVE-2018-11119
ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.
Ilias
after 5.3.4
MEDIUM 6.1
CVE-2018-10678
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers…
Mybb
Mitigation only
MEDIUM 6.1
CVE-2018-1000174
An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirec…
Google Login
after 1.3
MEDIUM 6.1
CVE-2018-1248
RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header inject…
Authentication Manager
after 8.3
MEDIUM 6.1
CVE-2017-18262
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shi…
Blackboard Learn
after 9.1
MEDIUM 6.1
CVE-2018-10100
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
WordPress
4.9.5+
MEDIUM 6.1
CVE-2018-10101
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
WordPress
4.9.5+
MEDIUM 6.1
CVE-2017-0363
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
Debian Linux
1.27.2 / 1.28.1+
MEDIUM 6.1
CVE-2017-0364
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
Debian Linux
1.27.2 / 1.28.1+
MEDIUM 6.1
CVE-2017-7153
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is aff…
Safari
4.2 / 7.2+
MEDIUM 6.1
CVE-2018-3819
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerab…
Kibana
5.6.7 / 6.1.3+
MEDIUM 6.1
CVE-2018-7674
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
Identity Manager
after 4.6
MEDIUM 6.1
CVE-2018-8937
An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI …
Open Audit
No fix yet
MEDIUM 6.5
CVE-2018-0924EPSS 8%
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 C…
Exchange Server
Patch available
MEDIUM 6.1
CVE-2018-1220
EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit thi…
Rsa Archer
6.2.0.8+
MEDIUM 6.1
CVE-2018-7473
Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attackers to redirect users to arbit…
Sowifi Hotspot Firmware
Mitigation only
MEDIUM 6.1
CVE-2017-14802
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects t…
Access Manager
after 4.3
MEDIUM 6.1
CVE-2015-3898EPSS 6%
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct …
Bonita Bpm Portal
6.5.3+
MEDIUM 6.1
CVE-2018-6324
F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login.
Radar
after 3.9.1
MEDIUM 6.1
CVE-2017-8945
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.
Icewall Federation Agent
Mitigation only
MEDIUM 6.1
CVE-2017-18178
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the tar…
Sitefinity
No fix yet