Vulnerabilities (CVE)

Filtered by CWE-601
Total 1137 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1019 1 Automatedlogic 1 Webctrl Server 2024-11-21 5.8 MEDIUM 5.2 MEDIUM
Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a maliciously crafted URL which could result in redirecting the user to a malicious webpage or downloading a malicious file.
CVE-2022-0869 1 Spirit-project 1 Spirit 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.
CVE-2022-0868 1 Uri.js Project 1 Uri.js 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
CVE-2022-0697 1 Archivy Project 1 Archivy 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.
CVE-2022-0692 1 Alltube Project 1 Alltube 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.
CVE-2022-0645 1 Posthog 1 Posthog 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.
CVE-2022-0597 1 Microweber 1 Microweber 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0560 1 Microweber 1 Microweber 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0283 1 Gitlab 1 Gitlab 2024-11-21 5.8 MEDIUM 4.7 MEDIUM
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.
CVE-2022-0235 3 Debian, Node-fetch Project, Siemens 3 Debian Linux, Node-fetch, Sinec Ins 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2022-0165 1 King-theme 1 Kingcomposer 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users
CVE-2022-0122 1 Digitalbazaar 1 Forge 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
forge is vulnerable to URL Redirection to Untrusted Site
CVE-2021-4348 1 Createit 1 Ultimate Gdpr \& Ccpa Compliance Toolkit 2024-11-21 N/A 7.5 HIGH
The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export_settings & import_settings functions in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to change plugin settings and conduct attacks such as redirecting visitors to malicious sites.
CVE-2021-4260 1 Oils-js Project 1 Oils-js 2024-11-21 N/A 6.3 MEDIUM
A vulnerability was found in oils-js. It has been declared as critical. This vulnerability affects unknown code of the file core/Web.js. The manipulation leads to open redirect. The attack can be initiated remotely. The name of the patch is fad8fbae824a7d367dacb90d56cb02c5cb999d42. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216268.
CVE-2021-4000 1 Showdoc 1 Showdoc 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
showdoc is vulnerable to URL Redirection to Untrusted Site
CVE-2021-46898 1 Vonautomatisch 1 Django Grappelli 2024-11-21 N/A 6.1 MEDIUM
views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack.
CVE-2021-46379 1 Dlink 2 Dir-850l, Dir-850l Firmware 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
CVE-2021-46366 1 Magnolia-cms 1 Magnolia Cms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.
CVE-2021-45408 1 Seeddms 1 Seeddms 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter.
CVE-2021-45328 1 Gitea 1 Gitea 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.