Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
HIGH 7.2 CVE-2026-48895 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an … Apisix 3.17.0+ Fix from $1,9502026-06-19 MEDIUM 6.1 CVE-2026-44915 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulner… Apisix 3.17.0+ Fix from $1,6002026-06-19 HIGH 7.2 CVE-2026-40961 A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirec… Airflow 3.2.2+ Fix from $1,9502026-06-01 MEDIUM 5.4 CVE-2026-48589 Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficie… Shiro 2.2.1+ Fix from $1,6002026-05-25 MEDIUM 5.4 CVE-2026-44598 With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. … Shiro 2.1.1+ Fix from $1,6002026-05-25 MEDIUM 6.1 CVE-2026-25854 Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects … Tomcat 9.0.116 / 10.1.53+ Fix from $1,6002026-04-09 MEDIUM 5.4 CVE-2025-27888 Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… Druid 31.0.2+ Fix from $1,6002025-03-20 MEDIUM 6.1 CVE-2023-46750 URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Sh… Shiro 1.13.0+ Fix from $1,6002023-12-14 MEDIUM 5.4 CVE-2023-42502 An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users co… Superset 3.0.0+ Fix from $1,6002023-11-28 MEDIUM 6.1 CVE-2023-41080EPSS 6% URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from… Tomcat after 10.1.12 Fix from $1,6002023-08-25 MEDIUM 5.4 CVE-2022-43721 An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site wh… Superset after 1.5.2 Fix from $1,6002023-01-16 MEDIUM 6.1 CVE-2022-47500 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache H… Helix after 1.0.4 Fix from $1,6002022-12-19 MEDIUM 6.1 CVE-2022-45402EPSS 82% In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint. Airflow 2.4.3+ Fix from $1,6002022-11-15 MEDIUM 6.1 CVE-2022-43985 In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint. Airflow 2.4.2+ Fix from $1,6002022-11-02 MEDIUM 6.1 CVE-2022-40754 In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint. Airflow after 2.3.4 Fix from $1,6002022-09-21 MEDIUM 6.1 CVE-2022-24969 bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic… Dubbo 2.6.12 / 2.7.15+ Fix from $1,6002022-06-09 MEDIUM 6.1 CVE-2021-25640 In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S… Dubbo 2.6.9 / 2.7.9+ Fix from $1,6002021-06-01 MEDIUM 6.1 CVE-2021-28125EPSS 64% Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open re… Superset after 1.0.1 Fix from $1,6002021-04-27 MEDIUM 6.1 CVE-2020-1927EPSS 57% In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded new… HTTP Server after 2.4.41 Fix from $1,6002020-04-02 MEDIUM 6.1 CVE-2019-10098EPSS 74% In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded new… HTTP Server after 2.4.39 Fix from $1,6002019-09-25 MEDIUM 6.1 CVE-2015-5241 After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect… Juddi Mitigation only Fix from $1,6002017-05-19