Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2025-70037
An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sen…
Twake
Mitigation only
CRITICAL 9.3
CVE-2026-29067
ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password rese…
Zitadel
4.7.1+
HIGH 8.1
CVE-2026-28681
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version…
Internet Routing Registry Daemon
4.4.5 / 4.5.1+
MEDIUM 6.1
CVE-2026-28413
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil…
Isurlinportal
2.1.0 / 3.1.0+
MEDIUM 6.1
CVE-2026-27982
An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default),…
Allauth
65.14.1+
MEDIUM 6.1
CVE-2026-25477
AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at t…
Affine
0.26.0+
MEDIUM 6.1
CVE-2026-27736
BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks val…
Bigbluebutton
3.0.20+
MEDIUM 6.9
CVE-2026-27738
The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic …
Patch available
MEDIUM 6.1
CVE-2026-28194
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
Teamcity
2025.11.3+
MEDIUM 6.1
CVE-2026-24847
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form mo…
Openemr
8.0.0+
MEDIUM 6.1
CVE-2026-3049
A vulnerability was detected in horilla-opensource horilla up to 1.0.2. This issue affects the function get of the file horilla_generics/global_searc…
Horilla
1.0.3+
HIGH 8.7
CVE-2026-25649
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 …
Traccar
after 6.11.1
MEDIUM 6.1
CVE-2026-27191
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.39 and below the redirect quer…
Feathers
5.0.40+
MEDIUM 6.1
CVE-2025-71244
SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visit…
Spip
4.3.9 / 4.4.5+
CRITICAL 9.0
CVE-2026-0573
An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorizatio…
Enterprise Server
3.14.22 / 3.15.17+
MEDIUM 6.1
CVE-2026-1296
The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to i…
Mitigation only
MEDIUM 6.1
CVE-2025-27900
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By pers…
Db2 Recovery Expert
Patch available
MEDIUM 5.4
CVE-2026-26003
FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through FastGPT/api/plugin/xxx witho…
Fastgpt
4.14.5+
MEDIUM 6.1
CVE-2026-25956
Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site whi…
Frappe
14.99.14 / 15.94.0+
MEDIUM 6.1
CVE-2026-24328
SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect th…
Business Server Pages
Mitigation only
MEDIUM 6.1
CVE-2026-24323
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sa…
Document Management System
Mitigation only
HIGH 8.1
CVE-2026-0508
The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the appli…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.5
CVE-2026-0484
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa…
Sap Basis
Mitigation only
MEDIUM 6.1
CVE-2025-66596
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
This product does not
properly validate request headers. W…
Fast\/tools
Mitigation only
MEDIUM 6.1
CVE-2026-2153
A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. E…
Doorman
after 0.6
MEDIUM 6.1
CVE-2026-25651
client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of clien…
Client Certificate Auth
1.0.0+
MEDIUM 6.1
CVE-2026-1970
A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipu…
Br 6258n Firmware
after 1.18
MEDIUM 6.1
CVE-2026-20123
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow…
Evolved Programmable Network Manager
3.10.6 / 8.1.1+
MEDIUM 6.1
CVE-2026-25149
Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler mi…
Qwik
1.19.0+
HIGH 7.4
CVE-2026-24052
Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification…
Claude Code
1.0.111+