Vulnerability index

Browse CVEs

1,441 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
MEDIUM 6.1 CVE-2025-70037 An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sen… Twake Mitigation only Fix from $1,6002026-03-09 CRITICAL 9.3 CVE-2026-29067 ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password rese… Zitadel 4.7.1+ Fix from $2,3002026-03-07 HIGH 8.1 CVE-2026-28681 Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version… Internet Routing Registry Daemon 4.4.5 / 4.5.1+ Fix from $1,9502026-03-06 MEDIUM 6.1 CVE-2026-28413 Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil… Isurlinportal 2.1.0 / 3.1.0+ Fix from $1,6002026-03-05 MEDIUM 6.1 CVE-2026-27982 An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default),… Allauth 65.14.1+ Fix from $1,6002026-03-05 MEDIUM 6.1 CVE-2026-25477 AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at t… Affine 0.26.0+ Fix from $1,6002026-03-02 MEDIUM 6.1 CVE-2026-27736 BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks val… Bigbluebutton 3.0.20+ Fix from $1,6002026-02-25 MEDIUM 6.9 CVE-2026-27738 The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic … Patch available Fix from $1,6002026-02-25 MEDIUM 6.1 CVE-2026-28194 In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow Teamcity 2025.11.3+ Fix from $1,6002026-02-25 MEDIUM 6.1 CVE-2026-24847 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form mo… Openemr 8.0.0+ Fix from $1,6002026-02-25 MEDIUM 6.1 CVE-2026-3049 A vulnerability was detected in horilla-opensource horilla up to 1.0.2. This issue affects the function get of the file horilla_generics/global_searc… Horilla 1.0.3+ Fix from $1,6002026-02-24 HIGH 8.7 CVE-2026-25649 Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 … Traccar after 6.11.1 Fix from $1,9502026-02-23 MEDIUM 6.1 CVE-2026-27191 Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.39 and below the redirect quer… Feathers 5.0.40+ Fix from $1,6002026-02-21 MEDIUM 6.1 CVE-2025-71244 SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visit… Spip 4.3.9 / 4.4.5+ Fix from $1,6002026-02-19 CRITICAL 9.0 CVE-2026-0573 An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorizatio… Enterprise Server 3.14.22 / 3.15.17+ Fix from $2,3002026-02-18 MEDIUM 6.1 CVE-2026-1296 The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to i… Mitigation only Fix from $1,6002026-02-18 MEDIUM 6.1 CVE-2025-27900 IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By pers… Db2 Recovery Expert Patch available Fix from $1,6002026-02-17 MEDIUM 5.4 CVE-2026-26003 FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through FastGPT/api/plugin/xxx witho… Fastgpt 4.14.5+ Fix from $1,6002026-02-10 MEDIUM 6.1 CVE-2026-25956 Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site whi… Frappe 14.99.14 / 15.94.0+ Fix from $1,6002026-02-10 MEDIUM 6.1 CVE-2026-24328 SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect th… Business Server Pages Mitigation only Fix from $1,6002026-02-10 MEDIUM 6.1 CVE-2026-24323 The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sa… Document Management System Mitigation only Fix from $1,6002026-02-10 HIGH 8.1 CVE-2026-0508 The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the appli… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-0484 Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa… Sap Basis Mitigation only Fix from $1,6002026-02-10 MEDIUM 6.1 CVE-2025-66596 A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate request headers. W… Fast\/tools Mitigation only Fix from $1,6002026-02-09 MEDIUM 6.1 CVE-2026-2153 A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. E… Doorman after 0.6 Fix from $1,6002026-02-08 MEDIUM 6.1 CVE-2026-25651 client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of clien… Client Certificate Auth 1.0.0+ Fix from $1,6002026-02-06 MEDIUM 6.1 CVE-2026-1970 A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipu… Br 6258n Firmware after 1.18 Fix from $1,6002026-02-05 MEDIUM 6.1 CVE-2026-20123 A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow… Evolved Programmable Network Manager 3.10.6 / 8.1.1+ Fix from $1,6002026-02-04 MEDIUM 6.1 CVE-2026-25149 Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler mi… Qwik 1.19.0+ Fix from $1,6002026-02-03 HIGH 7.4 CVE-2026-24052 Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification… Claude Code 1.0.111+ Fix from $1,9502026-02-03