Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2020-05-21 CVE-2020-1059 Open Redirect vulnerability in Microsoft Edge
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka 'Microsoft Edge Spoofing Vulnerability'.
network
low complexity
microsoft CWE-601
4.3
2020-05-16 CVE-2020-13121 Open Redirect vulnerability in Rcos Submitty
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
network
low complexity
rcos CWE-601
6.1
2020-05-14 CVE-2020-5409 Open Redirect vulnerability in Pivotal Software Concourse
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow.
network
low complexity
pivotal-software CWE-601
6.1
2020-05-13 CVE-2020-1997 Open Redirect vulnerability in Paloaltonetworks Pan-Os
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway.
network
low complexity
paloaltonetworks CWE-601
6.1
2020-05-13 CVE-2020-12699 Open Redirect vulnerability in DKD Direct Mail
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
network
low complexity
dkd CWE-601
6.1
2020-05-07 CVE-2020-11053 Open Redirect vulnerability in Oauth2 Proxy Project Oauth2 Proxy
In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability.
network
low complexity
oauth2-proxy-project CWE-601
6.1
2020-05-06 CVE-2020-3311 Open Redirect vulnerability in Cisco Firepower Management Center
A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
network
low complexity
cisco CWE-601
6.1
2020-05-06 CVE-2020-3178 Open Redirect vulnerability in Cisco Content Security Management Appliance
Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
network
low complexity
cisco CWE-601
6.1
2020-05-05 CVE-2020-12666 Open Redirect vulnerability in multiple products
macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.
network
low complexity
go-macaron fedoraproject CWE-601
6.1
2020-05-05 CVE-2020-11034 Open Redirect vulnerability in Glpi-Project Glpi
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp.
network
low complexity
glpi-project CWE-601
6.1