Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2020-06-18 CVE-2020-14446 Open Redirect vulnerability in Wso2 Identity Server and Identity Server AS KEY Manager
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0.
network
low complexity
wso2 CWE-601
6.1
2020-06-18 CVE-2020-3337 Open Redirect vulnerability in Cisco Umbrella
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page.
network
low complexity
cisco CWE-601
6.1
2020-06-10 CVE-2020-6266 Open Redirect vulnerability in SAP Fiori
SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation, leading to URL Redirection.
network
low complexity
sap CWE-601
5.4
2020-06-09 CVE-2020-1323 Open Redirect vulnerability in Microsoft Sharepoint Enterprise Server and Sharepoint Server
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.
network
low complexity
microsoft CWE-601
6.1
2020-06-09 CVE-2020-1220 Open Redirect vulnerability in Microsoft Edge
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
network
low complexity
microsoft CWE-601
6.1
2020-06-02 CVE-2020-10959 Open Redirect vulnerability in Mediawiki
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
network
low complexity
mediawiki CWE-601
6.1
2020-05-25 CVE-2020-13486 Open Redirect vulnerability in Verbb Knock
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
network
low complexity
verbb CWE-601
6.1
2020-05-21 CVE-2020-1059 Open Redirect vulnerability in Microsoft Edge
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka 'Microsoft Edge Spoofing Vulnerability'.
network
low complexity
microsoft CWE-601
4.3
2020-05-16 CVE-2020-13121 Open Redirect vulnerability in Rcos Submitty
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
network
low complexity
rcos CWE-601
6.1
2020-05-14 CVE-2020-5409 Open Redirect vulnerability in Pivotal Software Concourse
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow.
network
low complexity
pivotal-software CWE-601
6.1