Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Apisix HIGH 7.2
CVE-2026-48895

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an …

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Apisix MEDIUM 6.1
CVE-2026-44915

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulner…

Fix: 3.17.0+
Fix from $1,600 2026-06-19
Airflow HIGH 7.2
CVE-2026-40961

A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirec…

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Shiro MEDIUM 5.4
CVE-2026-48589

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficie…

Fix: 2.2.1+
Fix from $1,600 2026-05-25
Shiro MEDIUM 5.4
CVE-2026-44598

With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. …

Fix: 2.1.1+
Fix from $1,600 2026-05-25
Tomcat MEDIUM 6.1
CVE-2026-25854

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects …

Fix: 9.0.116 / 10.1.53+
Fix from $1,600 2026-04-09
Druid MEDIUM 5.4
CVE-2025-27888

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…

Fix: 31.0.2+
Fix from $1,600 2025-03-20
Shiro MEDIUM 6.1
CVE-2023-46750

URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Sh…

Fix: 1.13.0+
Fix from $1,600 2023-12-14
Superset MEDIUM 5.4
CVE-2023-42502

An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users co…

Fix: 3.0.0+
Fix from $1,600 2023-11-28
Tomcat MEDIUM 6.1
CVE-2023-41080EPSS 6%

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from…

Fix: after 10.1.12
Fix from $1,600 2023-08-25
Superset MEDIUM 5.4
CVE-2022-43721

An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site wh…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Helix MEDIUM 6.1
CVE-2022-47500

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache H…

Fix: after 1.0.4
Fix from $1,600 2022-12-19
Airflow MEDIUM 6.1
CVE-2022-45402EPSS 82%

In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.

Fix: 2.4.3+
Fix from $1,600 2022-11-15
Airflow MEDIUM 6.1
CVE-2022-43985

In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.

Fix: 2.4.2+
Fix from $1,600 2022-11-02
Airflow MEDIUM 6.1
CVE-2022-40754

In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.

Fix: after 2.3.4
Fix from $1,600 2022-09-21
Dubbo MEDIUM 6.1
CVE-2022-24969

bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic…

Fix: 2.6.12 / 2.7.15+
Fix from $1,600 2022-06-09
Dubbo MEDIUM 6.1
CVE-2021-25640

In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S…

Fix: 2.6.9 / 2.7.9+
Fix from $1,600 2021-06-01
Superset MEDIUM 6.1
CVE-2021-28125EPSS 64%

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open re…

Fix: after 1.0.1
Fix from $1,600 2021-04-27
HTTP Server MEDIUM 6.1
CVE-2020-1927EPSS 57%

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded new…

Fix: after 2.4.41
Fix from $1,600 2020-04-02
HTTP Server MEDIUM 6.1
CVE-2019-10098EPSS 74%

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded new…

Fix: after 2.4.39
Fix from $1,600 2019-09-25
Juddi MEDIUM 6.1
CVE-2015-5241

After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect…

Mitigation only
Fix from $1,600 2017-05-19