Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2026-7504
A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation …
Build Of Keycloak
26.4.12+
HIGH 7.3
CVE-2026-3872
A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect…
Build Of Keycloak
Mitigation only
MEDIUM 5.4
CVE-2026-2376
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by prov…
Quay
Patch available
MEDIUM 6.1
CVE-2024-8883
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is se…
Build Of Keycloak
Mitigation only
MEDIUM 6.1
CVE-2024-7260
An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are m…
Build Of Keycloak
24.0.7+
HIGH 7.1
CVE-2023-6291
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful …
Keycloak
22.0.7+
MEDIUM 6.1
CVE-2023-6927
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM respo…
Keycloak
Mitigation only
MEDIUM 6.1
CVE-2022-2237
A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso functio…
Keycloak Node.js Adapter
Mitigation only
MEDIUM 6.1
CVE-2021-3654EPSS 27%
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
Openstack Platform
21.2.3 / 22.2.3+
MEDIUM 6.1
CVE-2020-1723
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected ver…
Mobile Application Platform
Mitigation only
MEDIUM 5.3
CVE-2020-10775
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary we…
Ovirt Engine
after 4.4
MEDIUM 6.1
CVE-2014-3652
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
Keycloak
Patch available
MEDIUM 6.1
CVE-2018-14658
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.Red…
Keycloak
Mitigation only
MEDIUM 6.5
CVE-2017-15419
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by …
Enterprise Linux Desktop
63.0.3239.84+
HIGH 7.4
CVE-2017-3085
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redi…
Enterprise Linux
after 26.0.0.137
MEDIUM 6.5
CVE-2011-1594
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to ar…
Network Satellite
Patch available