Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,653 CVEs tagged with CWE-60126 Critical, 178 High, 1,343 Medium, 102 Low, 4 Unrated.

CVE-2021-29622

Published May 19, 2021

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's pre…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36365

Published May 19, 2021

Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32618

Published May 17, 2021

The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-24288

Published May 17, 2021

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially m…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27612

Published May 11, 2021

In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phish…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13662

Published May 5, 2021

Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue af…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-23015

Published May 3, 2021

An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29137

Published Apr 29, 2021

A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21998

Published Apr 27, 2021

In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to re…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28125

Published Apr 27, 2021

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener func…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29456

Published Apr 21, 2021

Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on (SSO) for your applications via a web portal. In versions 4…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21392

Published Apr 12, 2021

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before v…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24210

Published Apr 5, 2021

There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24165

Published Apr 5, 2021

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-9995

Published Apr 2, 2021

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Server 5.11. Processing a maliciously crafted URL ma…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29652

Published Apr 2, 2021

Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24550

Published Mar 31, 2021

An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27352

Published Mar 29, 2021

An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23888

Published Mar 26, 2021

Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12483

Published Mar 23, 2021

The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort
Showing 1,176-1,200 of 1,653 CVEsPage 48 of 67