Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-11-23 | CVE-2021-36332 | Open Redirect vulnerability in Dell EMC Cloud Link Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. | 5.4 |
2021-11-08 | CVE-2021-41733 | Open Redirect vulnerability in Oppia 3.1.4 Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them. | 6.1 |
2021-11-04 | CVE-2021-1500 | Open Redirect vulnerability in Cisco Collaboration Meeting Rooms and Webex Video Mesh A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. | 6.1 |
2021-11-01 | CVE-2021-43058 | Open Redirect vulnerability in Replicated Classic 2.41.0 An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. | 6.1 |
2021-10-27 | CVE-2021-34764 | Open Redirect vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. | 6.1 |
2021-10-19 | CVE-2021-3851 | Open Redirect vulnerability in Firefly-Iii Firefly III firefly-iii is vulnerable to URL Redirection to Untrusted Site | 5.4 |
2021-10-18 | CVE-2021-22942 | Open Redirect vulnerability in Rubyonrails Rails A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website. | 6.1 |
2021-10-14 | CVE-2021-22963 | Open Redirect vulnerability in Fastify Fastify-Static A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. | 6.1 |
2021-10-14 | CVE-2021-22964 | Open Redirect vulnerability in Fastify Fastify-Static 4.2.4/4.3.0/4.4.0 A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arbitrary websites via a double slash `//` followed by a domain: `http://localhost:3000//a//youtube.com/%2e%2e%2f%2e%2e`.A DOS vulnerability is possible if the URL contains invalid characters `curl --path-as-is "http://localhost:3000//^/.."`The issue shows up on all the `fastify-static` applications that set `redirect: true` option. | 8.8 |
2021-10-13 | CVE-2021-20806 | Open Redirect vulnerability in Cybozu Remote Service Manager Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | 6.1 |