Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,601 CVEs tagged with CWE-60125 Critical, 158 High, 1,319 Medium, 96 Low, 3 Unrated.

CVE-2025-61753

Published Oct 21, 2025

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable v…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62595

Published Oct 21, 2025

Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62428

Published Oct 16, 2025

Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host Header Injection in the /register and /confirm-email endpoi…

CVSS 8.8 · High

CVE-2025-62407

Published Oct 16, 2025

Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, if a specific type…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62379

Published Oct 15, 2025

Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace endpoint automatically assigns the redirect_to query paramet…

CVSS 3.1 · Low

CVE-2025-62361

Published Oct 13, 2025

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open Redirect vulnerability was identified in the control.php en…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11167

Published Oct 11, 2025

The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including,…

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-35059

Published Oct 9, 2025

Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0608

Published Oct 6, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forceful Browsing. This issue affects Logo Cloud: before 2025.…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-61606

Published Oct 2, 2025

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identified in the control.php endpoi…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54088

Published Oct 2, 2025

CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11240

Published Oct 2, 2025

An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub inst…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-61587

Published Oct 1, 2025

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis an…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-55017

Published Sep 30, 2025

Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to intercept authorization codes and gain unaut…

CVSS 7.5 · High

CVE-2025-57879

Published Sep 29, 2025

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a vict…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57878

Published Sep 29, 2025

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a vict…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57872

Published Sep 29, 2025

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a vict…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59426

Published Sep 25, 2025

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of the fi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58006

Published Sep 22, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Phishing.This issue affects WP Gravity For…

CVSS 4.7 · Medium

CVE-2025-7702

Published Sep 19, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows E…

CVSS 4.7 · Medium

CVE-2025-9084

Published Sep 15, 2025

Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9072

Published Sep 15, 2025

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 1,601 CVEsPage 14 of 65