Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2021-09-07 CVE-2021-39501 Open Redirect vulnerability in Eyoucms 1.5.4
EyouCMS 1.5.4 is vulnerable to Open Redirect.
network
low complexity
eyoucms CWE-601
6.1
2021-09-07 CVE-2021-38123 Open Redirect vulnerability in Microfocus Network Automation
Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05.
network
low complexity
microfocus CWE-601
6.1
2021-09-06 CVE-2021-25737 Open Redirect vulnerability in Kubernetes
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node.
network
low complexity
kubernetes CWE-601
4.8
2021-09-03 CVE-2021-39191 Open Redirect vulnerability in multiple products
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider.
network
low complexity
openidc fedoraproject debian CWE-601
6.1
2021-08-30 CVE-2021-38343 Open Redirect vulnerability in Kylephillips Nested Pages
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.
network
low complexity
kylephillips CWE-601
6.1
2021-08-25 CVE-2021-39112 Open Redirect vulnerability in Atlassian products
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature.
network
low complexity
atlassian CWE-601
4.8
2021-08-24 CVE-2021-30888 Open Redirect vulnerability in Apple products
An information leakage issue was addressed.
network
low complexity
apple CWE-601
7.4
2021-08-13 CVE-2021-37352 Open Redirect vulnerability in Nagios XI
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing.
network
low complexity
nagios CWE-601
6.1
2021-08-12 CVE-2021-37699 Open Redirect vulnerability in Vercel Next.Js
Next.js is an open source website development framework to be used with the React library.
network
low complexity
vercel CWE-601
6.1
2021-08-11 CVE-2021-22098 Open Redirect vulnerability in Cloudfoundry User Account and Authentication
UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability.
network
low complexity
cloudfoundry CWE-601
6.1