Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2023-06-05 CVE-2015-10114 Open Redirect vulnerability in Woocommerce Woosidebars
A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress.
network
low complexity
woocommerce CWE-601
6.1
2023-06-05 CVE-2015-10112 Open Redirect vulnerability in Woocommerce Wooframework Branding
A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress.
network
low complexity
woocommerce CWE-601
6.1
2023-06-02 CVE-2023-29540 Open Redirect vulnerability in Mozilla Firefox and Focus
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>.
network
low complexity
mozilla CWE-601
6.1
2023-05-31 CVE-2023-34224 Open Redirect vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
network
low complexity
jetbrains CWE-601
4.8
2023-05-30 CVE-2023-32218 Open Redirect vulnerability in Avaya IX Workforce Engagement 15.2.7.1195
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
network
low complexity
avaya CWE-601
6.1
2023-05-30 CVE-2023-23754 Open Redirect vulnerability in Joomla Joomla!
An issue was discovered in Joomla! 4.2.0 through 4.3.1.
network
low complexity
joomla CWE-601
6.1
2023-05-30 CVE-2023-20884 Open Redirect vulnerability in VMWare products
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
network
low complexity
vmware CWE-601
6.1
2023-05-25 CVE-2023-28370 Open Redirect vulnerability in Tornadoweb Tornado
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
network
low complexity
tornadoweb CWE-601
6.1
2023-05-22 CVE-2023-31245 Open Redirect vulnerability in Snapone Orvc
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection.
network
low complexity
snapone CWE-601
6.1
2023-05-15 CVE-2023-32068 Open Redirect vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-601
6.1