Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2015-2749
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduc…
Drupal
Patch available
MEDIUM 6.1
CVE-2015-2750
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to a…
Drupal
Patch available
MEDIUM 6.1
CVE-2015-5054
Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary …
Banner Student
No fix yet
MEDIUM 5.4
CVE-2017-1449
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim t…
Emptoris Sourcing
Mitigation only
MEDIUM 6.1
CVE-2017-1450
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim t…
Emptoris Sourcing
Mitigation only
MEDIUM 6.1
CVE-2017-14038
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
Crushftp
after 7.7.0
MEDIUM 6.1
CVE-2017-1195
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. …
Curam Social Program Management
Patch available
MEDIUM 6.1
CVE-2017-1489
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authenticatio…
Tivoli Access Manager For E Business
Mitigation only
HIGH 7.4
CVE-2017-3085
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redi…
Enterprise Linux
after 26.0.0.137
MEDIUM 5.4
CVE-2016-8949
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack…
Emptoris Strategic Supply Management
Mitigation only
MEDIUM 5.4
CVE-2017-1448
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack…
Emptoris Strategic Supply Management
Mitigation only
MEDIUM 6.1
CVE-2017-12138
XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.
Xoops
Mitigation only
MEDIUM 5.4
CVE-2017-11725
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.
Secret Server
after 10.2.000018
MEDIUM 6.1
CVE-2017-11718
There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.
Metinfo
after 5.3.17
MEDIUM 5.4
CVE-2017-1287
IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit…
Rhapsody Design Manager
Patch available
MEDIUM 6.1
CVE-2017-11586
dayrui FineCms 5.0.9 has URL Redirector Abuse via the url parameter in a sync action, related to controllers/Weixin.php.
Finecms
after 5.0.9
MEDIUM 6.1
CVE-2017-1223
IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit…
Bigfix Platform
Mitigation only
MEDIUM 6.1
CVE-2017-1000070
The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAu…
Oauth2 Proxy
after 2.1
MEDIUM 6.1
CVE-2017-1000013
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
phpMyAdmin
Patch available
MEDIUM 6.1
CVE-2017-1000027
Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting i…
Sme Server
Mitigation only
MEDIUM 6.1
CVE-2016-8947
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a …
Emptoris Sourcing
Mitigation only
MEDIUM 5.4
CVE-2016-8953
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a …
Emptoris Sourcing
Patch available
MEDIUM 6.1
CVE-2017-8621
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnera…
Exchange Server
Patch available
MEDIUM 6.1
CVE-2017-1398
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker to conduct phishing attacks, …
Websphere Commerce
Mitigation only
MEDIUM 6.1
CVE-2017-2217
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites an…
Download Manager
after 2.9.50
MEDIUM 6.1
CVE-2017-5002
EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an open redirect vulnerability. A remote unprivileged attacker may…
Rsa Archer Egrc
Mitigation only
MEDIUM 6.1
CVE-2017-6018
An open redirect issue was discovered in B. Braun Medical SpaceCom module, which is integrated into the SpaceStation docking station: SpaceStation wi…
Station Firmware
Mitigation only
MEDIUM 6.1
CVE-2016-10365
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that re…
Kibana
after 5.0.0
MEDIUM 6.1
CVE-2017-8451
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a li…
Kibana
after 5.3.0
MEDIUM 6.1
CVE-2017-9464
An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sit…
Piwigo
after 2.9.0