Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,580 CVEs tagged with CWE-60124 Critical, 149 High, 1,308 Medium, 96 Low, 3 Unrated.

CVE-2019-10856

Published Apr 4, 2019

In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15180

Published Apr 2, 2019

qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8913

Published Apr 1, 2019

Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18109

Published Mar 29, 2019

The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10255

Published Mar 28, 2019

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login p…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3850

Published Mar 26, 2019

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4035

Published Mar 22, 2019

IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, they can send a link to ICN users…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9837

Published Mar 21, 2019

Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri field in an OAuth authorization…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7416

Published Mar 21, 2019

XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnerable.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17422

Published Mar 7, 2019

dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1939

Published Mar 5, 2019

IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a r…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10742

Published Feb 17, 2019

Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5915

Published Feb 13, 2019

Open redirect vulnerability in OpenAM (Open Source Edition) 13.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially craf…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3912

Published Jan 30, 2019

An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6780

Published Jan 24, 2019

The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and noreferrer.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16191

Published Jan 9, 2019

Open redirect vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3.0.4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC-C…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16174

Published Jan 9, 2019

Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vect…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15798

Published Dec 19, 2018

Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a li…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1,351-1,375 of 1,580 CVEsPage 55 of 64