Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 5.1 CVE-2026-42350 Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Kargo is vulnerable to open red… Mitigation only Fix from $1,6002026-05-08 MEDIUM 5.3 CVE-2026-3318 Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in the login form endpoint, wher… Mitigation only Fix from $1,6002026-05-08 CRITICAL 9.6 CVE-2026-43941 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink… Electerm after 3.8.15 Fix from $2,3002026-05-08 MEDIUM 5.1 CVE-2026-42259 Saltcorn is an extensible, open source, no-code database application builder. Prior to versions 1.4.6, 1.5.6, and 1.6.0-beta.5, Saltcorn validates th… Mitigation only Fix from $1,6002026-05-07 CRITICAL 9.6 CVE-2026-6795 URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. … Mitigation only Fix from $2,3002026-05-07 HIGH 8.2 CVE-2026-41670 Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionCon… Mitigation only Fix from $1,9502026-05-07 MEDIUM 5.3 CVE-2026-40332 Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application incorrectly interprets paths… No fix yet Fix from $1,6002026-05-06 HIGH 7.7 CVE-2026-43576 OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pi… Openclaw 2026.4.5+ Fix from $1,9502026-05-06 MEDIUM 6.1 CVE-2025-61669 Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is … Jupyter Server 2.18.0+ Fix from $1,6002026-05-05 MEDIUM 6.1 CVE-2026-42230 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth c… N8n 1.123.32 / 2.17.4+ Fix from $1,6002026-05-04 CRITICAL 9.3 CVE-2026-33102 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 365 Copilot Mitigation only Fix from $2,3002026-04-23 HIGH 8.1 CVE-2026-40905 LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, a password reset poisoning vulnerability was identified in the application… Mitigation only Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-34315 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are … Weblogic Server Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.1 CVE-2026-34283 Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected… Identity Manager Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.1 CVE-2026-34284 Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versio… Business Process Management Suite Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.9 CVE-2026-40299 next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-need… Patch available Fix from $1,6002026-04-17 MEDIUM 6.1 CVE-2026-40255 AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-ne… HTTP Server 7.8.1+ Fix from $1,6002026-04-16 MEDIUM 5.4 CVE-2026-40096 immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the s… Immich 2.7.3+ Fix from $1,6002026-04-15 MEDIUM 6.1 CVE-2026-34257 Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if access… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2026-6203 The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insuffic… Mitigation only Fix from $1,6002026-04-13 MEDIUM 5.3 CVE-2026-39940 ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCRM application to create a lin… Mitigation only Fix from $1,6002026-04-13 MEDIUM 6.1 CVE-2026-32932 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows a… Chamilo Lms 1.11.38+ Fix from $1,6002026-04-10 MEDIUM 5.3 CVE-2026-22560 An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters with… Rocket.chat 8.4.0+ Fix from $1,6002026-04-10 MEDIUM 6.1 CVE-2026-25854 Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects … Tomcat 9.0.116 / 10.1.53+ Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2026-39985 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging … Loris 27.0.3+ Fix from $1,6002026-04-09 MEDIUM 6.5 CVE-2026-40037 OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies … Openclaw 2026.4.8+ Fix from $1,6002026-04-08 CRITICAL 9.6 CVE-2026-23818 A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacke… Aruba Networking Private 5g Core 1.25.3.1+ Fix from $2,3002026-04-07 MEDIUM 6.1 CVE-2026-35473 WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php … Wegia 3.6.9+ Fix from $1,6002026-04-06 MEDIUM 6.1 CVE-2026-35474 WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The redirect parameter is taken dir… Wegia 3.6.9+ Fix from $1,6002026-04-06 MEDIUM 6.1 CVE-2026-35475 WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET with no URL validation or whi… Wegia 3.6.9+ Fix from $1,6002026-04-06