Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,653 CVEs tagged with CWE-60126 Critical, 178 High, 1,343 Medium, 102 Low, 4 Unrated.

CVE-2021-20534

Published Jul 15, 2021

IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially craf…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-35037

Published Jul 12, 2021

Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An attacker may craft a URL that…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24406

Published Jul 6, 2021

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful logi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23401

Published Jul 5, 2021

This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providin…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-34807

Published Jul 2, 2021

An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker would need to have obtained a va…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-23182

Published Jul 2, 2021

The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32721

Published Jun 29, 2021

PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to craft phishing links and other open redirects by exploiting…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20105

Published Jun 29, 2021

Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34254

Published Jun 28, 2021

Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25655

Published Jun 24, 2021

A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions in…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-18660

Published Jun 23, 2021

GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32956

Published Jun 18, 2021

Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a u…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24358

Published Jun 14, 2021

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, le…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22903

Published Jun 11, 2021

The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can c…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23393

Published Jun 11, 2021

This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitr…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-18268

Published Jun 7, 2021

Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25640

Published Jun 1, 2021

In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32645

Published May 27, 2021

Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirect…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23387

Published May 24, 2021

The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://e…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1358

Published May 22, 2021

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerabil…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,151-1,175 of 1,653 CVEsPage 47 of 67