Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,592 CVEs tagged with CWE-60125 Critical, 153 High, 1,315 Medium, 96 Low, 3 Unrated.

CVE-2019-14403

Published Jul 30, 2019

cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20867

Published Jul 30, 2019

cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010290

Published Jul 16, 2019

Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The componen…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1075

Published Jul 15, 2019

A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12621

Published Jul 5, 2019

An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5969

Published Jul 5, 2019

Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5965

Published Jul 5, 2019

Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10721

Published Jul 3, 2019

BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13175

Published Jul 2, 2019

Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addition to the public readthedocs.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10133

Published Jun 26, 2019

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-4153

Published Jun 25, 2019

IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a special…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4201

Published Jun 6, 2019

IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to vis…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13384

Published Jun 4, 2019

A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequ…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5871

Published May 22, 2019

Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6781

Published May 17, 2019

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5946

Published May 17, 2019

Open redirect vulnerability in Cybozu Garoon 4.2.4 to 4.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the Login Screen.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,326-1,350 of 1,592 CVEsPage 54 of 64