Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,592 CVEs tagged with CWE-60125 Critical, 153 High, 1,315 Medium, 96 Low, 3 Unrated.

CVE-2025-42924

Published Nov 11, 2025

SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled by the a…

CVSS 6.1 · Medium

CVE-2025-42893

Published Nov 11, 2025

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attack…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64481

Published Nov 7, 2025

Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open re…

CVSS 2.7 · Low

CVE-2025-63784

Published Nov 7, 2025

An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerabili…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12789

Published Nov 7, 2025

A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri parameter associated with the open…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-64116

Published Oct 30, 2025

Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without validation, allowing attacker…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64115

Published Oct 30, 2025

Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header value directly for redirects in mu…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50736

Published Oct 30, 2025

An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external webs…

CVSS 6.1 · Medium

CVE-2025-64101

Published Oct 29, 2025

Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utiliz…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62981

Published Oct 27, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Phishing.This issue affects WP Gravity Forms Zoho…

CVSS 4.7 · Medium

CVE-2025-62716

Published Oct 24, 2025

Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_path query parameter allows attackers to supply arbitrary sch…

CVSS 8.1 · High

CVE-2025-10355

Published Oct 23, 2025

Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious URL using a manipulated redirection parameter, potentially le…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-60151

Published Oct 22, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Phishing.This issue affects WP Gravity Forms HubSpot: fro…

CVSS 4.7 · Medium

CVE-2025-61753

Published Oct 21, 2025

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable v…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62595

Published Oct 21, 2025

Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62428

Published Oct 16, 2025

Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host Header Injection in the /register and /confirm-email endpoi…

CVSS 8.8 · High

CVE-2025-62407

Published Oct 16, 2025

Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, if a specific type…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62379

Published Oct 15, 2025

Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace endpoint automatically assigns the redirect_to query paramet…

CVSS 3.1 · Low

CVE-2025-62361

Published Oct 13, 2025

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open Redirect vulnerability was identified in the control.php en…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11167

Published Oct 11, 2025

The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including,…

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
17.5
Showing 301-325 of 1,592 CVEsPage 13 of 64