Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,646 CVEs tagged with CWE-60126 Critical, 178 High, 1,337 Medium, 102 Low, 3 Unrated.

CVE-2018-14381

Published Jul 18, 2018

Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0594

Published Jul 11, 2018

Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attack…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000504

Published Jun 26, 2018

Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows admins to execute any PHP file in the filesystem. This att…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11408

Published Jun 13, 2018

The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an O…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16652

Published Jun 13, 2018

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthentica…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5389

Published Jun 11, 2018

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9078

Published Jun 11, 2018

Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations agains…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-16224

Published Jun 7, 2018

st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1748

Published Jun 4, 2018

IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3743

Published Jun 1, 2018

Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8094

Published May 22, 2018

Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next param…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11119

Published May 17, 2018

ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10678

Published May 13, 2018

MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attack…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000174

Published May 8, 2018

An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL af…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1248

Published May 8, 2018

RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18262

Published Apr 30, 2018

Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrate…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,476-1,500 of 1,646 CVEsPage 60 of 66