Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2026-47991
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redirect) vulnerability that could …
Experience Manager
6.5.25.0 / 2026.5.0+
MEDIUM 5.3
CVE-2026-47347
Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it h…
Patch available
MEDIUM 6.1
CVE-2026-41844
A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to…
Spring Framework
5.3.49 / 6.1.28+
MEDIUM 6.1
CVE-2026-21826
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header …
Digital Experience Compose
Mitigation only
MEDIUM 6.1
CVE-2026-10861
An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key…
Misp
2.5.39+
MEDIUM 6.1
CVE-2026-10856
A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpret…
Misp
2.5.39+
MEDIUM 6.1
CVE-2026-41569
authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter usi…
Authentik
2026.2.3+
MEDIUM 6.1
CVE-2026-40181
React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigg…
React Router
6.30.4 / 7.14.1+
MEDIUM 6.1
CVE-2026-45278
Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redire…
User Oidc
8.2.2+
HIGH 7.2
CVE-2026-40961
A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirec…
Airflow
3.2.2+
MEDIUM 6.1
CVE-2026-49380
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
Teamcity
2026.1+
MEDIUM 6.1
CVE-2026-45307
Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to…
Mitigation only
MEDIUM 6.1
CVE-2026-44681
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's O…
Authlib
1.6.12+
MEDIUM 5.4
CVE-2026-45335
WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …
Mitigation only
HIGH 7.1
CVE-2026-44833
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to m…
Snipe It
8.4.1+
MEDIUM 5.4
CVE-2026-48589
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login.
In affected versions, insufficie…
Shiro
2.2.1+
MEDIUM 5.4
CVE-2026-44598
With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro.
…
Shiro
2.1.1+
MEDIUM 6.1
CVE-2026-47070
Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect handler in src/hackney_h3.erl p…
Hackney
4.0.1+
MEDIUM 6.1
CVE-2026-40295
Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the Fa…
Devise
5.0.4+
MEDIUM 5.0
CVE-2026-9245
Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect vi…
Devolutions Server
2025.3.22.0 / 2026.1.19.0+
HIGH 8.2
CVE-2025-26483
Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this…
Powerflex Appliance Intelligent Catalog
3.7.8.0 / 48.383.00+
HIGH 8.1
CVE-2026-7504
A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation …
Build Of Keycloak
26.4.12+
MEDIUM 6.1
CVE-2025-65954
SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logou…
Simplesamlphp Module Casserver
6.3.1+
HIGH 7.1
CVE-2026-45037
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly t…
Tabby
1.0.232+
MEDIUM 6.1
CVE-2026-42207
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo…
Mitigation only
MEDIUM 5.7
CVE-2026-44520
Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to …
Mitigation only
HIGH 7.0
CVE-2026-44503
The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to st…
Mitigation only
MEDIUM 6.1
CVE-2026-44437
The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a…
Angular Cli
19.2.25 / 20.3.25+
HIGH 8.1
CVE-2026-45055
CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at boots…
Mitigation only
MEDIUM 6.1
CVE-2026-44372
Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cros…
Nitro
2.13.4 / 3.0.260429+