Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2017-07-11 CVE-2017-8621 Open Redirect vulnerability in Microsoft Exchange Server 2010/2013/2016
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability".
network
low complexity
microsoft CWE-601
6.1
2017-07-10 CVE-2017-1398 Open Redirect vulnerability in IBM Websphere Commerce
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.1
2017-07-07 CVE-2017-2217 Open Redirect vulnerability in Wpdownloadmanager Wordpress Download Manager
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
low complexity
wpdownloadmanager CWE-601
6.1
2017-07-07 CVE-2017-5002 Open Redirect vulnerability in EMC RSA Archer Egrc
EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an open redirect vulnerability.
network
low complexity
emc CWE-601
6.1
2017-06-30 CVE-2017-6018 Open Redirect vulnerability in Bbraun Station Firmware
An open redirect issue was discovered in B.
network
low complexity
bbraun CWE-601
6.1
2017-06-16 CVE-2017-8451 Open Redirect vulnerability in Elastic Kibana
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
network
low complexity
elastic CWE-601
6.1
2017-06-16 CVE-2016-10365 Open Redirect vulnerability in Elastic Kibana
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
network
low complexity
elastic CWE-601
6.1
2017-06-14 CVE-2017-9464 Open Redirect vulnerability in Piwigo
An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks.
network
low complexity
piwigo CWE-601
6.1
2017-06-13 CVE-2017-6670 Open Redirect vulnerability in Cisco Unified Communications Domain Manager 8.1(7)Er1
A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue.
network
low complexity
cisco CWE-601
6.1
2017-06-09 CVE-2016-7831 Open Redirect vulnerability in Fenrir-Inc Sleipnir 4.5.3
Sleipnir 4 Black Edition for Mac 4.5.3 and earlier and Sleipnir 4 for Mac 4.5.3 and earlier (Mac App Store) may allow a remote attacker to spoof the URL display via a specially crafted webpage.
network
low complexity
fenrir-inc CWE-601
6.1