Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 5.4 CVE-2016-0329 Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, … Emptoris Sourcing after 10.1.0.0 Fix from $1,6002018-02-02 MEDIUM 6.1 CVE-2018-6520 SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL. Simplesamlphp 1.15.1+ Fix from $1,6002018-02-02 MEDIUM 6.1 CVE-2017-2166 Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishin… Groupsession after 4.7.0 Fix from $1,6002018-01-26 MEDIUM 6.1 CVE-2018-6200 vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter. Vbulletin after 4.2.5 Fix from $1,6002018-01-25 MEDIUM 6.1 CVE-2018-0097 A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious … Prime Infrastructure Mitigation only Fix from $1,6002018-01-18 MEDIUM 6.1 CVE-2017-1534 IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By pe… Security Access Manager For Web Firmware Mitigation only Fix from $1,6002018-01-10 MEDIUM 6.1 CVE-2017-1668 IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persu… Security Key Lifecycle Manager Mitigation only Fix from $1,6002018-01-09 MEDIUM 6.1 CVE-2017-1000484 By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the … Plone Mitigation only Fix from $1,6002018-01-03 MEDIUM 6.1 CVE-2017-1000481 When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. Aft… Plone Mitigation only Fix from $1,6002018-01-03 MEDIUM 6.1 CVE-2017-1000434 Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allows for a redirect to an attac… Furikake No fix yet Fix from $1,6002018-01-02 MEDIUM 6.1 CVE-2017-1558 IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vic… Maximo Asset Management Mitigation only Fix from $1,6002017-12-13 MEDIUM 6.1 CVE-2017-16679 URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21… Sap Kernel Mitigation only Fix from $1,6002017-12-12 MEDIUM 6.1 CVE-2017-11482 The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vuln… Kibana Mitigation only Fix from $1,6002017-12-08 MEDIUM 6.1 CVE-2017-3105 Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2. Robohelp 12.0.4.460 / 2017.0.1+ Fix from $1,6002017-12-01 MEDIUM 6.1 CVE-2017-12344 Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM conf… Data Center Network Manager Mitigation only Fix from $1,6002017-11-30 MEDIUM 6.1 CVE-2017-1000163 The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, w… Phoenix Mitigation only Fix from $1,6002017-11-17 HIGH 8.8 CVE-2017-11879EPSS 9% ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP… Asp.net Core Patch available Fix from $1,9502017-11-15 MEDIUM 6.1 CVE-2017-16761 An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites. Buildmaster 5.8.2+ Fix from $1,6002017-11-10 MEDIUM 6.1 CVE-2017-14358 A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.… Arcsight Enterprise Security Manager Mitigation only Fix from $1,6002017-10-31 MEDIUM 6.1 CVE-2015-6961 Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct phishing … Web2py Patch available Fix from $1,6002017-10-18 MEDIUM 6.1 CVE-2015-7943 Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABj… Drupal Mitigation only Fix from $1,6002017-10-18 HIGH 8.8 CVE-2017-1000117EPSS 78% A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that … Git after 2.7.5 Fix from $1,9502017-10-05 MEDIUM 6.1 CVE-2017-8047 In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possibl… Cf Release after 273 Fix from $1,6002017-10-04 MEDIUM 6.1 CVE-2017-14524 Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web s… Documentum Administrator Mitigation only Fix from $1,6002017-09-28 MEDIUM 6.1 CVE-2017-14525 Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites an… Documentum Administrator Mitigation only Fix from $1,6002017-09-28 MEDIUM 6.1 CVE-2015-4668EPSS 7% Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac… Xsuite No fix yet Fix from $1,6002017-09-25 MEDIUM 5.4 CVE-2017-14725 Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php. WordPress after 4.8.1 Fix from $1,6002017-09-23 MEDIUM 6.1 CVE-2015-5608 Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1. Joomla\! Mitigation only Fix from $1,6002017-09-20 MEDIUM 6.1 CVE-2015-3880 Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web… Phpbb after 3.0.14 Fix from $1,6002017-09-19 MEDIUM 6.1 CVE-2017-1002150 python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection Python Fedora after 0.8.0 Fix from $1,6002017-09-14