Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2026-47991 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redirect) vulnerability that could … Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 5.3 CVE-2026-47347 Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it h… Patch available Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-41844 A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-21826 HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header … Digital Experience Compose Mitigation only Fix from $1,6002026-06-05 MEDIUM 6.1 CVE-2026-10861 An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key… Misp 2.5.39+ Fix from $1,6002026-06-04 MEDIUM 6.1 CVE-2026-10856 A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpret… Misp 2.5.39+ Fix from $1,6002026-06-04 MEDIUM 6.1 CVE-2026-41569 authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter usi… Authentik 2026.2.3+ Fix from $1,6002026-06-02 MEDIUM 6.1 CVE-2026-40181 React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigg… React Router 6.30.4 / 7.14.1+ Fix from $1,6002026-06-02 MEDIUM 6.1 CVE-2026-45278 Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redire… User Oidc 8.2.2+ Fix from $1,6002026-06-01 HIGH 7.2 CVE-2026-40961 A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirec… Airflow 3.2.2+ Fix from $1,9502026-06-01 MEDIUM 6.1 CVE-2026-49380 In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible Teamcity 2026.1+ Fix from $1,6002026-05-29 MEDIUM 6.1 CVE-2026-45307 Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to… Mitigation only Fix from $1,6002026-05-28 MEDIUM 6.1 CVE-2026-44681 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's O… Authlib 1.6.12+ Fix from $1,6002026-05-27 MEDIUM 5.4 CVE-2026-45335 WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php … Mitigation only Fix from $1,6002026-05-27 HIGH 7.1 CVE-2026-44833 Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to m… Snipe It 8.4.1+ Fix from $1,9502026-05-26 MEDIUM 5.4 CVE-2026-48589 Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficie… Shiro 2.2.1+ Fix from $1,6002026-05-25 MEDIUM 5.4 CVE-2026-44598 With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. … Shiro 2.1.1+ Fix from $1,6002026-05-25 MEDIUM 6.1 CVE-2026-47070 Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect handler in src/hackney_h3.erl p… Hackney 4.0.1+ Fix from $1,6002026-05-25 MEDIUM 6.1 CVE-2026-40295 Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the Fa… Devise 5.0.4+ Fix from $1,6002026-05-22 MEDIUM 5.0 CVE-2026-9245 Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect vi… Devolutions Server 2025.3.22.0 / 2026.1.19.0+ Fix from $1,6002026-05-22 HIGH 8.2 CVE-2025-26483 Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this… Powerflex Appliance Intelligent Catalog 3.7.8.0 / 48.383.00+ Fix from $1,9502026-05-22 HIGH 8.1 CVE-2026-7504 A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation … Build Of Keycloak 26.4.12+ Fix from $1,9502026-05-19 MEDIUM 6.1 CVE-2025-65954 SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logou… Simplesamlphp Module Casserver 6.3.1+ Fix from $1,6002026-05-18 HIGH 7.1 CVE-2026-45037 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly t… Tabby 1.0.232+ Fix from $1,9502026-05-15 MEDIUM 6.1 CVE-2026-42207 Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo… Mitigation only Fix from $1,6002026-05-15 MEDIUM 5.7 CVE-2026-44520 Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to … Mitigation only Fix from $1,6002026-05-14 HIGH 7.0 CVE-2026-44503 The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to st… Mitigation only Fix from $1,9502026-05-14 MEDIUM 6.1 CVE-2026-44437 The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a… Angular Cli 19.2.25 / 20.3.25+ Fix from $1,6002026-05-13 HIGH 8.1 CVE-2026-45055 CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at boots… Mitigation only Fix from $1,9502026-05-13 MEDIUM 6.1 CVE-2026-44372 Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cros… Nitro 2.13.4 / 3.0.260429+ Fix from $1,6002026-05-13