Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,653 CVEs tagged with CWE-60126 Critical, 178 High, 1,343 Medium, 102 Low, 4 Unrated.

CVE-2025-20382

Published Dec 3, 2025

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.10, 10.0.2503.8, and 9.3.2411.120, a low-privileged user t…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58044

Published Dec 1, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-13819

Published Dec 1, 2025

Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to arbitrary external websites via a crafted parameter, facili…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-66062

Published Nov 21, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allows Phishing.This issue affects WP YouTube Lyte: from n/a th…

CVSS 3.4 · Low

CVE-2024-8527

Published Nov 19, 2025

Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user sessions.

CVSS 8.6 · High

CVE-2025-63828

Published Nov 18, 2025

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-40545

Published Nov 18, 2025

SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirec…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-13983

Published Nov 14, 2025

Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security seve…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64754

Published Nov 13, 2025

Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for…

CVSS 2.7 · Low

CVE-2025-20355

Published Nov 13, 2025

A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthenticated, remote attacker to redirect a user to a malicious…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-64716

Published Nov 13, 2025

Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. Prior to version 1.23.0, when using subrequest aut…

CVSS 5.1 · Medium

CVE-2025-20378

Published Nov 12, 2025

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9.3.2411.111, and 9.3.2408.121, an unauthenticated attacker…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-42924

Published Nov 11, 2025

SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled by the a…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-42893

Published Nov 11, 2025

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attack…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-64481

Published Nov 7, 2025

Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open re…

CVSS 2.7 · Low

CVE-2025-63784

Published Nov 7, 2025

An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerabili…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12789

Published Nov 7, 2025

A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri parameter associated with the open…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-64116

Published Oct 30, 2025

Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without validation, allowing attacker…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64115

Published Oct 30, 2025

Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header value directly for redirects in mu…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50736

Published Oct 30, 2025

An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external webs…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-64101

Published Oct 29, 2025

Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utiliz…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62981

Published Oct 27, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Phishing.This issue affects WP Gravity Forms Zoho…

CVSS 4.7 · Medium

CVE-2025-62716

Published Oct 24, 2025

Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_path query parameter allows attackers to supply arbitrary sch…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Showing 351-375 of 1,653 CVEsPage 15 of 67