CWE-601
1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low
URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users. |
1Mcafee 1Epolicy Orchestrator Jun 17, 2026 Mar 26, 2021 N/A· v4 6.3 MEDIUM· v3 4.9 MEDIUM· v2 Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which could steal informati...Show more |
The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters. |
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not...Show more |
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that Login Handling is susceptible to open redirection whic...Show more |
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's s...Show more |
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a us...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Mar 10, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vuln...Show more |
1Inetsoftware 1I Net Clear Reports Jun 17, 2026 Mar 9, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect. |
1Zope 1Products.pluggableauthservice Jun 17, 2026 Mar 8, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciously crafted link to t...Show more |
Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release process." In Pollbot before version 1.4.4 there is an open redirection v...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Feb 26, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided...Show more |
3Aiohttp DebianFedoraproject3Aiohttp Debian LinuxFedoraJun 17, 2026 Feb 26, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could red...Show more |
The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring. |
1Asus 1Askey Rtf8115vw Firmware Jun 17, 2026 Feb 19, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header. |
1Mbconnectline 2Mbconnect24 Mymbconnect24Jun 17, 2026 Feb 16, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php. |
1F5 2Big Ip Advanced Web Application Firewall Big Ip Application Security ManagerJun 17, 2026 Feb 12, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2, when receiving a unauthenticated...Show more |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Feb 11, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host...Show more |
2Open Emr Phpgacl Project2Openemr PhpgaclJun 17, 2026 Feb 10, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially craf...Show more |
SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. |