Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2021-11-30 CVE-2021-42564 Open Redirect vulnerability in Cryptshare Server
An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' substring in the editor parameter.
network
low complexity
cryptshare CWE-601
5.4
2021-11-24 CVE-2021-43777 Open Redirect vulnerability in Redash
Redash is a package for data visualization and sharing.
network
low complexity
redash CWE-601
6.1
2021-11-23 CVE-2021-38000 Open Redirect vulnerability in multiple products
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-601
6.1
2021-11-23 CVE-2021-36332 Open Redirect vulnerability in Dell EMC Cloud Link
Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability.
network
low complexity
dell CWE-601
5.4
2021-11-08 CVE-2021-41733 Open Redirect vulnerability in Oppia 3.1.4
Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.
network
low complexity
oppia CWE-601
6.1
2021-11-04 CVE-2021-1500 Open Redirect vulnerability in Cisco Collaboration Meeting Rooms and Webex Video Mesh
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
network
low complexity
cisco CWE-601
6.1
2021-11-01 CVE-2021-43058 Open Redirect vulnerability in Replicated Classic 2.41.0
An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing.
network
low complexity
replicated CWE-601
6.1
2021-10-27 CVE-2021-34764 Open Redirect vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack.
network
low complexity
cisco CWE-601
6.1
2021-10-19 CVE-2021-3851 Open Redirect vulnerability in Firefly-Iii Firefly III
firefly-iii is vulnerable to URL Redirection to Untrusted Site
network
low complexity
firefly-iii CWE-601
5.4
2021-10-18 CVE-2021-22942 Open Redirect vulnerability in Rubyonrails Rails
A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.
network
low complexity
rubyonrails CWE-601
6.1