CWE-601
1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low
URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect us...Show more |
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attac...Show more |
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the login url, which expose the application...Show more |
1Synacor 1Zimbra Collaboration Suite Jun 17, 2026 Dec 15, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing. |
openwhyd is vulnerable to URL Redirection to Untrusted Site |
The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirecti...Show more |
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or pro...Show more |
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers |
showdoc is vulnerable to URL Redirection to Untrusted Site |
showdoc is vulnerable to URL Redirection to Untrusted Site |
1Cryptshare 1Cryptshare Server Jun 17, 2026 Nov 30, 2021 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any UR...Show more |
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 23, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. |
Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, directing end user to arbitrary and poten...Show more |
Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them. |
1Cisco 2Collaboration Meeting Rooms Webex Video MeshJun 17, 2026 Nov 4, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input vali...Show more |
1Replicated 1Replicated Classic Jun 17, 2026 Nov 1, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exploit this vulnerability, an attacker could send a link that has a specially crafted URL and convince...Show more |
1Cisco 3Firepower Management Center Virtual Appliance Firepower Threat DefenseSourcefire Defense CenterJun 17, 2026 Oct 27, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For mo...Show more |
1Cisco 3Firepower Management Center Virtual Appliance Firepower Threat DefenseSourcefire Defense CenterJun 17, 2026 Oct 27, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For mo...Show more |
firefly-iii is vulnerable to URL Redirection to Untrusted Site |