Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2020-08-28 CVE-2020-5623 Open Redirect vulnerability in Nitori 6.0.2/6.0.4
NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary website via the vulnerable App.
network
nitori CWE-601
5.8
2020-08-26 CVE-2020-24598 Open Redirect vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.21.
network
joomla CWE-601
5.8
2020-08-25 CVE-2020-5541 Open Redirect vulnerability in Cybersolutions Cybermail 6.0/7.0
Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks via a specially crafted URL.
network
low complexity
cybersolutions CWE-601
6.1
2020-08-24 CVE-2020-10775 Open Redirect vulnerability in multiple products
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks.
network
high complexity
oracle redhat CWE-601
5.3
2020-08-24 CVE-2020-4598 Open Redirect vulnerability in IBM Security Guardium Insights 2.0.1
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
ibm CWE-601
5.8
2020-08-19 CVE-2020-4653 Open Redirect vulnerability in IBM Planning Analytics 2.0
IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
ibm CWE-601
5.8
2020-07-30 CVE-2020-15129 Open Redirect vulnerability in Traefik 1.0
In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header.
network
high complexity
traefik CWE-601
4.0
2020-07-23 CVE-2020-7520 Open Redirect vulnerability in Schneider-Electric Software Update Utility
A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine.
network
high complexity
schneider-electric CWE-601
4.0
2020-07-22 CVE-2020-8559 Open Redirect vulnerability in Kubernetes
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
network
low complexity
kubernetes CWE-601
6.8
2020-07-14 CVE-2019-12783 Open Redirect vulnerability in Verint Impact 360
An issue was discovered in Verint Impact 360 15.1.
network
verint CWE-601
5.8