Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2026-35410 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login… Directus 11.16.1+ Fix from $1,6002026-04-06 MEDIUM 6.1 CVE-2026-35404 Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a redirect_url GET parameter t… Openedx after 2026-04-02 Fix from $1,6002026-04-06 MEDIUM 6.1 CVE-2026-35472 WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php … Wegia 3.6.9+ Fix from $1,6002026-04-06 MEDIUM 6.1 CVE-2026-35396 WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php … Wegia 3.6.9+ Fix from $1,6002026-04-06 MEDIUM 6.1 CVE-2026-35398 WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php … Wegia 3.6.9+ Fix from $1,6002026-04-06 MEDIUM 6.1 CVE-2025-61166 An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL. Signinghub No fix yet Fix from $1,6002026-04-06 HIGH 8.8 CVE-2026-33510 Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login… Homarr 1.57.0+ Fix from $1,9502026-04-06 HIGH 7.5 CVE-2018-25245 7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings … No fix yet Fix from $1,9502026-04-04 MEDIUM 6.1 CVE-2026-33709 JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in… Jupyterhub 5.4.4+ Fix from $1,6002026-04-03 MEDIUM 6.1 CVE-2026-5467 A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request … Casdoor Mitigation only Fix from $1,6002026-04-03 MEDIUM 6.1 CVE-2026-34847 hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. … Hoppscotch 2026.3.0+ Fix from $1,6002026-04-02 CRITICAL 9.6 CVE-2026-34931 hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfilt… Hoppscotch 2026.3.0+ Fix from $2,3002026-04-02 MEDIUM 6.1 CVE-2026-34083 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server contains a code-level vulnerabi… Signal K Server 2.24.0+ Fix from $1,6002026-04-02 HIGH 7.3 CVE-2026-3872 A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect… Build Of Keycloak Mitigation only Fix from $1,9502026-04-02 MEDIUM 6.1 CVE-2024-58342 XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the … Xenforo 2.2.17+ Fix from $1,6002026-04-01 MEDIUM 6.1 CVE-2026-34442 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout ve… Freescout 1.8.211+ Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2026-32113 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2026-33885 Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redir… Statamic 5.73.16 / 6.7.2+ Fix from $1,6002026-03-27 MEDIUM 6.1 CVE-2026-33868 Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redi… Mastodon 4.3.21 / 4.4.15+ Fix from $1,6002026-03-27 HIGH 8.8 CVE-2026-33506 Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a … Polis 26.2.0+ Fix from $1,9502026-03-26 MEDIUM 6.1 CVE-2026-33397 The Angular SSR is a server-rise rendering tool for Angular applications. Versions on the 22.x branch prior to 22.0.0-next.2, the 21.x branch prior t… Angular Cli 20.3.21 / 21.2.3+ Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-33296 WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a us… Avideo 26.0+ Fix from $1,6002026-03-22 MEDIUM 6.1 CVE-2026-29105 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCR… Suitecrm 7.15.1 / 8.9.3+ Fix from $1,6002026-03-19 MEDIUM 6.1 CVE-2026-20994 URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token. Account 15.5.01.1+ Fix from $1,6002026-03-16 MEDIUM 5.4 CVE-2026-2376 A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by prov… Quay Patch available Fix from $1,6002026-03-12 MEDIUM 6.1 CVE-2026-3824 IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visit… Organization Portal System Mitigation only Fix from $1,6002026-03-11 MEDIUM 6.1 CVE-2026-23817 A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbit… Arubaos Cx 10.10.1180 / 10.13.1161+ Fix from $1,6002026-03-11 MEDIUM 6.1 CVE-2026-31819 Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and… Sylius 1.9.12 / 1.10.16+ Fix from $1,6002026-03-10 MEDIUM 6.1 CVE-2026-28512 Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback … Pocket Id 2.4.0+ Fix from $1,6002026-03-10 MEDIUM 6.1 CVE-2025-70032 An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. Sunbirded Portal Mitigation only Fix from $1,6002026-03-09