Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,644 CVEs tagged with CWE-60126 Critical, 177 High, 1,336 Medium, 102 Low, 3 Unrated.

CVE-2020-24598

Published Aug 26, 2020

An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5541

Published Aug 25, 2020

Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks via a specially crafted URL.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4653

Published Aug 19, 2020

IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15129

Published Jul 30, 2020

In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The Traefik…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7520

Published Jul 23, 2020

A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8559

Published Jul 22, 2020

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests tha…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12783

Published Jul 14, 2020

An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunc…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20901

Published Jul 13, 2020

The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may us…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5607

Published Jul 10, 2020

Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11882

Published Jul 7, 2020

The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. The purpose of this activity is to handle deeplinks that can…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4037

Published Jun 29, 2020

In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authenticati…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18897

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18891

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14454

Published Jun 19, 2020

An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-000…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3337

Published Jun 18, 2020

A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improp…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6266

Published Jun 10, 2020

SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation, leading to URL Redirection.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1220

Published Jun 9, 2020

A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing…

CVSS 6.1 · Medium

CVE-2020-10959

Published Jun 2, 2020

resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,251-1,275 of 1,644 CVEsPage 51 of 66