Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2025-02-20 CVE-2024-13888 The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56.
network
low complexity
CWE-601
7.2
2025-02-18 CVE-2025-1269 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.This issue affects Liman MYS: before 2.1.1 - 1010.
low complexity
CWE-601
4.8
2025-02-11 CVE-2025-23363 A vulnerability has been identified in Teamcenter (All versions < V14.3.0.0).
network
low complexity
CWE-601
7.4
2025-02-11 CVE-2025-24868 The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation.
network
low complexity
CWE-601
7.1
2025-02-02 CVE-2025-0970 A vulnerability was found in Zenvia Movidesk up to 25.01.22.
network
low complexity
CWE-601
4.3
2025-01-27 CVE-2025-24741 Open Redirect vulnerability in Logon KB Support
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in KB Support KB Support.
network
low complexity
logon CWE-601
6.1
2025-01-24 CVE-2025-0705 A vulnerability has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic.
network
low complexity
CWE-601
4.3
2025-01-21 CVE-2025-24020 Open Redirect vulnerability in Wegia
WeGIA is a Web manager for charitable institutions.
network
low complexity
wegia CWE-601
6.1
2024-12-18 CVE-2024-45082 Open Redirect vulnerability in IBM Cognos Analytics
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
low complexity
ibm CWE-601
5.2
2024-12-09 CVE-2024-38485 Open Redirect vulnerability in Dell Elastic Cloud Storage
Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability.
network
low complexity
dell CWE-601
4.3