Vulnerability index

Browse CVEs

1,447 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2017-6670 A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a use… Unified Communications Domain Manager Mitigation only Fix from $1,6002017-06-13 MEDIUM 6.1 CVE-2016-7831 Sleipnir 4 Black Edition for Mac 4.5.3 and earlier and Sleipnir 4 for Mac 4.5.3 and earlier (Mac App Store) may allow a remote attacker to spoof the … Sleipnir after 4.5.3 Fix from $1,6002017-06-09 MEDIUM 6.1 CVE-2017-9296 Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows remote attackers to redirect … Device Manager after 8.5.2 Fix from $1,6002017-05-29 MEDIUM 6.1 CVE-2017-9297 Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to redirect users to arbitrary web sites. Device Manager after 8.5.2 Fix from $1,6002017-05-29 MEDIUM 6.1 CVE-2017-7343 An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter. Fortiportal after 4.0.0 Fix from $1,6002017-05-27 MEDIUM 6.1 CVE-2017-3126 An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthor… Fortianalyzer Firmware Mitigation only Fix from $1,6002017-05-27 MEDIUM 6.1 CVE-2015-3190 With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or e… Cf Release after 209 Fix from $1,6002017-05-25 MEDIUM 5.4 CVE-2017-1159 IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vi… Business Process Manager Patch available Fix from $1,6002017-05-22 MEDIUM 6.1 CVE-2017-2497 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "iBooks" c… Iphone Os after 10.12.4 Fix from $1,6002017-05-22 MEDIUM 6.1 CVE-2015-5241 After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect… Juddi Mitigation only Fix from $1,6002017-05-19 HIGH 8.6 CVE-2017-9062 In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API. WordPress after 4.7.4 Fix from $1,9502017-05-18 MEDIUM 6.1 CVE-2015-4070 Open redirect vulnerability in the proxyimages function in wowproxy.php in the Wow Moodboard Lite plugin 1.1.1.1 for WordPress allows remote attacker… Wow Moodboard Lite Mitigation only Fix from $1,6002017-05-17 MEDIUM 6.1 CVE-2016-4857 Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.1… Splunk after 6.4.2 Fix from $1,6002017-05-12 MEDIUM 6.1 CVE-2016-4859 Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.1… Splunk after 6.4.2 Fix from $1,6002017-05-12 MEDIUM 6.1 CVE-2016-9099 Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 ar… Advanced Secure Gateway 6.5.10.6 / 6.7.2.1+ Fix from $1,6002017-05-11 HIGH 8.8 CVE-2017-1156 IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to … Websphere Portal Patch available Fix from $1,9502017-05-05 MEDIUM 6.1 CVE-2015-9058 Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites a… Proxmox Mail Gateway after 4.0-4 Fix from $1,6002017-05-03 MEDIUM 6.1 CVE-2016-10368 Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a cer… Opsview No fix yet Fix from $1,6002017-05-03 MEDIUM 5.4 CVE-2017-3528EPSS 15% Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, et… Applications Framework Patch available Fix from $1,6002017-04-24 MEDIUM 6.1 CVE-2016-4075 Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL. Opera Browser No fix yet Fix from $1,6002017-04-21 MEDIUM 6.1 CVE-2016-1213 The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites. Garoon after 4.2.1 Fix from $1,6002017-04-20 MEDIUM 5.4 CVE-2016-0228 IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts. A… Marketing Platform Patch available Fix from $1,6002017-04-17 MEDIUM 6.1 CVE-2016-4334 Jive before 2016.3.1 has an open redirect from the external-link.jspa page. Jive after 2016.3 Fix from $1,6002017-04-10 MEDIUM 6.1 CVE-2017-3889 A vulnerability in the web interface of the Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to redirect a user to a… Registered Envelope Service Mitigation only Fix from $1,6002017-04-07 MEDIUM 6.1 CVE-2017-6604 A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redi… Unified Computing System Mitigation only Fix from $1,6002017-04-07 MEDIUM 6.1 CVE-2017-7233 Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. T… Django Mitigation only Fix from $1,6002017-04-04 MEDIUM 6.1 CVE-2017-7234 A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` v… Django Mitigation only Fix from $1,6002017-04-04 MEDIUM 6.1 CVE-2016-10315 Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.0… Al3g Firmware No fix yet Fix from $1,6002017-04-03 MEDIUM 6.1 CVE-2016-10316 Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.0… Al3g Firmware No fix yet Fix from $1,6002017-04-03 MEDIUM 6.1 CVE-2017-7266 Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain … Security Monkey after 0.7.0 Fix from $1,6002017-03-26