Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,592 CVEs tagged with CWE-60125 Critical, 153 High, 1,315 Medium, 96 Low, 3 Unrated.

CVE-2019-5978

Published Sep 12, 2019

Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Sch…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16220

Published Sep 11, 2019

In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14223

Published Sep 6, 2019

An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15818

Published Aug 30, 2019

The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15774

Published Aug 29, 2019

The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15772

Published Aug 29, 2019

The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10751

Published Aug 23, 2019

All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13422

Published Aug 23, 2019

Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11589

Published Aug 23, 2019

The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11585

Published Aug 23, 2019

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect us…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1954

Published Aug 8, 2019

A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired we…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10372

Published Aug 7, 2019

An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins afte…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10769

Published Aug 5, 2019

cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18441

Published Aug 2, 2019

cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18414

Published Aug 2, 2019

cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9140

Published Aug 1, 2019

When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirect…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20929

Published Aug 1, 2019

cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,301-1,325 of 1,592 CVEsPage 53 of 64