Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2021-09-30 CVE-2021-41826 Open Redirect vulnerability in Place Placeos Authentication
PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.
network
low complexity
place CWE-601
6.1
2021-09-14 CVE-2021-23052 Open Redirect vulnerability in F5 Big-Ip Access Policy Manager
On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy.
network
low complexity
f5 CWE-601
6.1
2021-09-13 CVE-2021-22526 Open Redirect vulnerability in Microfocus Access Manager 5.0
Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
network
low complexity
microfocus CWE-601
6.1
2021-09-12 CVE-2021-23435 Open Redirect vulnerability in Thoughtbot Clearance
This affects the package clearance before 2.5.0.
network
low complexity
thoughtbot CWE-601
6.1
2021-09-07 CVE-2021-39501 Open Redirect vulnerability in Eyoucms 1.5.4
EyouCMS 1.5.4 is vulnerable to Open Redirect.
network
low complexity
eyoucms CWE-601
6.1
2021-09-07 CVE-2021-38123 Open Redirect vulnerability in Microfocus Network Automation
Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05.
network
low complexity
microfocus CWE-601
6.1
2021-09-06 CVE-2021-25737 Open Redirect vulnerability in Kubernetes
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node.
network
low complexity
kubernetes CWE-601
4.8
2021-08-30 CVE-2021-38343 Open Redirect vulnerability in Kylephillips Nested Pages
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.
network
low complexity
kylephillips CWE-601
6.1
2021-08-25 CVE-2021-39112 Open Redirect vulnerability in Atlassian products
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature.
network
low complexity
atlassian CWE-601
4.8
2021-08-24 CVE-2021-30888 Open Redirect vulnerability in Apple products
An information leakage issue was addressed.
network
low complexity
apple CWE-601
7.4