Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,646 CVEs tagged with CWE-60126 Critical, 178 High, 1,337 Medium, 102 Low, 3 Unrated.

CVE-2020-26275

Published Dec 21, 2020

The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Se…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25901

Published Dec 18, 2020

Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4849

Published Dec 15, 2020

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker co…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26836

Published Dec 9, 2020

SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29565

Published Dec 4, 2020

An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parame…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26232

Published Nov 24, 2020

Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server could redirect the browser to a different website. All jupyt…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28726

Published Nov 24, 2020

Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26215

Published Nov 18, 2020

Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All no…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26219

Published Nov 11, 2020

touchbase.ai before version 2.0 is vulnerable to Open Redirect. Impacts can be many, and vary from theft of information and credentials, to the redirection to malicious websites c…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26161

Published Oct 26, 2020

In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3558

Published Oct 21, 2020

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a m…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6365

Published Oct 15, 2020

SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insuf…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24551

Published Oct 14, 2020

IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to redirect to any malicious site and steal the victim's login cr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15241

Published Oct 8, 2020

TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the tern…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15242

Published Oct 8, 2020

Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur t…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15234

Published Oct 2, 2020

ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0 Client's registered redirect URLs and the redirect URL prov…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15233

Published Oct 2, 2020

ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite from version 0.30.2 and before version 0.34.1, there is an issue in which an an attacker can ove…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15974

Published Sep 23, 2020

A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vu…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5627

Published Sep 9, 2020

Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,226-1,250 of 1,646 CVEsPage 50 of 66