Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,601 CVEs tagged with CWE-60125 Critical, 158 High, 1,319 Medium, 96 Low, 3 Unrated.

CVE-2015-9540

Published Jan 4, 2020

Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20225

Published Jan 2, 2020

MyBB before 1.8.22 allows an open redirect on login.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6035

Published Dec 26, 2019

Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted pag…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6025

Published Dec 26, 2019

Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type 6.3.9…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6021

Published Dec 26, 2019

Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing att…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6020

Published Dec 26, 2019

Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18781

Published Dec 18, 2019

An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8791

Published Dec 18, 2019

An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Ver…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19775

Published Dec 18, 2019

The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3652

Published Dec 15, 2019

JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19709

Published Dec 11, 2019

MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the as…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19703

Published Dec 10, 2019

In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1000107

Published Dec 10, 2019

inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1000108

Published Dec 10, 2019

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client dat…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1002102

Published Dec 5, 2019

Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streami…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-18451

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14857

Published Nov 26, 2019

A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2213

Published Nov 22, 2019

Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing att…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15073

Published Nov 20, 2019

An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13257

Published Nov 18, 2019

The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,276-1,300 of 1,601 CVEsPage 52 of 65