Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2022-04-19 CVE-2022-24858 Open Redirect vulnerability in Nextauth.Js Next-Auth
next-auth v3 users before version 3.29.2 are impacted.
network
low complexity
nextauth-js CWE-601
6.1
2022-04-19 CVE-2022-0645 Open Redirect vulnerability in Posthog
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.
network
low complexity
posthog CWE-601
6.1
2022-04-13 CVE-2022-27256 Open Redirect vulnerability in Hubzilla
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
network
low complexity
hubzilla CWE-601
6.1
2022-04-06 CVE-2022-27109 Open Redirect vulnerability in Orangehrm 4.10
OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
network
low complexity
orangehrm CWE-601
5.4
2022-04-06 CVE-2022-27110 Open Redirect vulnerability in Orangehrm 4.10
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
network
low complexity
orangehrm CWE-601
5.4
2022-04-05 CVE-2022-27463 Open Redirect vulnerability in Wwbn Avideo
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.
network
low complexity
wwbn CWE-601
6.1
2022-04-04 CVE-2022-1233 Open Redirect vulnerability in Uri.Js Project Uri.Js
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
network
low complexity
uri-js-project CWE-601
6.1
2022-03-30 CVE-2022-23798 Open Redirect vulnerability in Joomla Joomla!
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0.
network
low complexity
joomla CWE-601
6.1
2022-03-30 CVE-2022-26950 Open Redirect vulnerability in RSA Archer
Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability.
network
low complexity
rsa CWE-601
6.1
2022-03-28 CVE-2005-10001 Open Redirect vulnerability in Broadcom Symantec Siteminder 4.5.0/4.5.1
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical.
network
low complexity
broadcom CWE-601
6.1