Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2026-35410
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login…
Directus
11.16.1+
MEDIUM 6.1
CVE-2026-35404
Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a redirect_url GET parameter t…
Openedx
after 2026-04-02
MEDIUM 6.1
CVE-2026-35472
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …
Wegia
3.6.9+
MEDIUM 6.1
CVE-2026-35396
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …
Wegia
3.6.9+
MEDIUM 6.1
CVE-2026-35398
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php …
Wegia
3.6.9+
MEDIUM 6.1
CVE-2025-61166
An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL.
Signinghub
No fix yet
HIGH 8.8
CVE-2026-33510
Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login…
Homarr
1.57.0+
HIGH 7.5
CVE-2018-25245
7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings …
No fix yet
MEDIUM 6.1
CVE-2026-33709
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in…
Jupyterhub
5.4.4+
MEDIUM 6.1
CVE-2026-5467
A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request …
Casdoor
Mitigation only
MEDIUM 6.1
CVE-2026-34847
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. …
Hoppscotch
2026.3.0+
CRITICAL 9.6
CVE-2026-34931
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfilt…
Hoppscotch
2026.3.0+
MEDIUM 6.1
CVE-2026-34083
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server contains a code-level vulnerabi…
Signal K Server
2.24.0+
HIGH 7.3
CVE-2026-3872
A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect…
Build Of Keycloak
Mitigation only
MEDIUM 6.1
CVE-2024-58342
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the …
Xenforo
2.2.17+
MEDIUM 6.1
CVE-2026-34442
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout ve…
Freescout
1.8.211+
MEDIUM 6.1
CVE-2026-32113
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…
Discourse
2026.1.3 / 2026.2.2+
MEDIUM 6.1
CVE-2026-33885
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redir…
Statamic
5.73.16 / 6.7.2+
MEDIUM 6.1
CVE-2026-33868
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redi…
Mastodon
4.3.21 / 4.4.15+
HIGH 8.8
CVE-2026-33506
Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a …
Polis
26.2.0+
MEDIUM 6.1
CVE-2026-33397
The Angular SSR is a server-rise rendering tool for Angular applications. Versions on the 22.x branch prior to 22.0.0-next.2, the 21.x branch prior t…
Angular Cli
20.3.21 / 21.2.3+
MEDIUM 6.1
CVE-2026-33296
WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a us…
Avideo
26.0+
MEDIUM 6.1
CVE-2026-29105
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCR…
Suitecrm
7.15.1 / 8.9.3+
MEDIUM 6.1
CVE-2026-20994
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
Account
15.5.01.1+
MEDIUM 5.4
CVE-2026-2376
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by prov…
Quay
Patch available
MEDIUM 6.1
CVE-2026-3824
IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visit…
Organization Portal System
Mitigation only
MEDIUM 6.1
CVE-2026-23817
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbit…
Arubaos Cx
10.10.1180 / 10.13.1161+
MEDIUM 6.1
CVE-2026-31819
Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and…
Sylius
1.9.12 / 1.10.16+
MEDIUM 6.1
CVE-2026-28512
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback …
Pocket Id
2.4.0+
MEDIUM 6.1
CVE-2025-70032
An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
Sunbirded Portal
Mitigation only