Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,653 CVEs tagged with CWE-60126 Critical, 178 High, 1,343 Medium, 102 Low, 4 Unrated.

CVE-2021-21377

Published Mar 23, 2021

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switch…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21338

Published Mar 23, 2021

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that Login Handlin…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14831

Published Mar 19, 2021

A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subs…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14830

Published Mar 19, 2021

A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21491

Published Mar 10, 2021

SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a mali…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28150

Published Mar 9, 2021

I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21337

Published Mar 8, 2021

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulne…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21354

Published Mar 8, 2021

Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release process." In Pollbot before ver…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21273

Published Feb 26, 2021

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before v…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-3189

Published Feb 19, 2021

The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22881

Published Feb 11, 2021

The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13565

Published Feb 10, 2021

An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.0.0 (commit babec93f600ff1394f…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21478

Published Feb 9, 2021

SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21476

Published Feb 9, 2021

SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-22840

Published Feb 9, 2021

Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to pa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25757

Published Feb 3, 2021

In JetBrains Hub before 2020.1.12629, an open redirect was possible.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21291

Published Feb 2, 2021

OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29537

Published Jan 29, 2021

Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and con…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22873

Published Jan 26, 2021

Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had p…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1218

Published Jan 20, 2021

A vulnerability in the web management interface of Cisco Smart Software Manager satellite could allow an authenticated, remote attacker to redirect a user to an undesired web page…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,201-1,225 of 1,653 CVEsPage 49 of 67