Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2026-48895
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The attacker could manipulate some client headers to perform an …
Apisix
3.17.0+
MEDIUM 6.1
CVE-2026-44915
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The default configuration of cas-auth in Apache APISIX is vulner…
Apisix
3.17.0+
HIGH 7.2
CVE-2026-40961
A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirec…
Airflow
3.2.2+
MEDIUM 5.4
CVE-2026-48589
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login.
In affected versions, insufficie…
Shiro
2.2.1+
MEDIUM 5.4
CVE-2026-44598
With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro.
…
Shiro
2.1.1+
MEDIUM 6.1
CVE-2026-25854
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects …
Tomcat
9.0.116 / 10.1.53+
MEDIUM 5.4
CVE-2025-27888
Severity: medium (5.8) / important
Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
Druid
31.0.2+
MEDIUM 6.1
CVE-2023-46750
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro.
Mitigation: Update to Apache Sh…
Shiro
1.13.0+
MEDIUM 5.4
CVE-2023-42502
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users co…
Superset
3.0.0+
MEDIUM 6.1
CVE-2023-41080EPSS 6%
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from…
Tomcat
after 10.1.12
MEDIUM 5.4
CVE-2022-43721
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site wh…
Superset
after 1.5.2
MEDIUM 6.1
CVE-2022-47500
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache H…
Helix
after 1.0.4
MEDIUM 6.1
CVE-2022-45402EPSS 82%
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.
Airflow
2.4.3+
MEDIUM 6.1
CVE-2022-43985
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.
Airflow
2.4.2+
MEDIUM 6.1
CVE-2022-40754
In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.
Airflow
after 2.3.4
MEDIUM 6.1
CVE-2022-24969
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic…
Dubbo
2.6.12 / 2.7.15+
MEDIUM 6.1
CVE-2021-25640
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S…
Dubbo
2.6.9 / 2.7.9+
MEDIUM 6.1
CVE-2021-28125EPSS 64%
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open re…
Superset
after 1.0.1
MEDIUM 6.1
CVE-2020-1927EPSS 57%
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded new…
HTTP Server
after 2.4.41
MEDIUM 6.1
CVE-2019-10098EPSS 74%
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded new…
HTTP Server
after 2.4.39
MEDIUM 6.1
CVE-2015-5241
After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect…
Juddi
Mitigation only