Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.1
CVE-2026-42350
Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Kargo is vulnerable to open red…
Mitigation only
MEDIUM 5.3
CVE-2026-3318
Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in the login form endpoint, wher…
Mitigation only
CRITICAL 9.6
CVE-2026-43941
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink…
Electerm
after 3.8.15
MEDIUM 5.1
CVE-2026-42259
Saltcorn is an extensible, open source, no-code database application builder. Prior to versions 1.4.6, 1.5.6, and 1.6.0-beta.5, Saltcorn validates th…
Mitigation only
CRITICAL 9.6
CVE-2026-6795
URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection.
…
Mitigation only
HIGH 8.2
CVE-2026-41670
Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionCon…
Mitigation only
MEDIUM 5.3
CVE-2026-40332
Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application incorrectly interprets paths…
No fix yet
HIGH 7.7
CVE-2026-43576
OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pi…
Openclaw
2026.4.5+
MEDIUM 6.1
CVE-2025-61669
Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is …
Jupyter Server
2.18.0+
MEDIUM 6.1
CVE-2026-42230
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth c…
N8n
1.123.32 / 2.17.4+
CRITICAL 9.3
CVE-2026-33102
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
Mitigation only
HIGH 8.1
CVE-2026-40905
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, a password reset poisoning vulnerability was identified in the application…
Mitigation only
MEDIUM 6.5
CVE-2026-34315
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are …
Weblogic Server
Mitigation only
MEDIUM 6.1
CVE-2026-34283
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected…
Identity Manager
Mitigation only
MEDIUM 6.1
CVE-2026-34284
Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versio…
Business Process Management Suite
Mitigation only
MEDIUM 6.9
CVE-2026-40299
next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-need…
Patch available
MEDIUM 6.1
CVE-2026-40255
AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-ne…
HTTP Server
7.8.1+
MEDIUM 5.4
CVE-2026-40096
immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the s…
Immich
2.7.3+
MEDIUM 6.1
CVE-2026-34257
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if access…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2026-6203
The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insuffic…
Mitigation only
MEDIUM 5.3
CVE-2026-39940
ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCRM application to create a lin…
Mitigation only
MEDIUM 6.1
CVE-2026-32932
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows a…
Chamilo Lms
1.11.38+
MEDIUM 5.3
CVE-2026-22560
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters with…
Rocket.chat
8.4.0+
MEDIUM 6.1
CVE-2026-25854
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects …
Tomcat
9.0.116 / 10.1.53+
MEDIUM 6.1
CVE-2026-39985
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …
Loris
27.0.3+
MEDIUM 6.5
CVE-2026-40037
OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies …
Openclaw
2026.4.8+
CRITICAL 9.6
CVE-2026-23818
A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacke…
Aruba Networking Private 5g Core
1.25.3.1+
MEDIUM 6.1
CVE-2026-35473
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …
Wegia
3.6.9+
MEDIUM 6.1
CVE-2026-35474
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The redirect parameter is taken dir…
Wegia
3.6.9+
MEDIUM 6.1
CVE-2026-35475
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET with no URL validation or whi…
Wegia
3.6.9+