Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2023-12-18 CVE-2023-6927 Open Redirect vulnerability in Redhat Keycloak and Single Sign-On
A flaw was found in Keycloak.
network
low complexity
redhat CWE-601
6.1
2023-12-16 CVE-2020-17484 Open Redirect vulnerability in Uffizio GPS Tracker
An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.
network
low complexity
uffizio CWE-601
6.1
2023-12-13 CVE-2023-50771 Open Redirect vulnerability in Jenkins Openid
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
network
low complexity
jenkins CWE-601
6.1
2023-12-09 CVE-2023-28874 Open Redirect vulnerability in Seafile 9.0.6
The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.
network
low complexity
seafile CWE-601
6.1
2023-12-08 CVE-2023-48928 Open Redirect vulnerability in Franklin-Electric System Sentinel Anyware 1.6.24.492
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect.
network
low complexity
franklin-electric CWE-601
6.1
2023-12-06 CVE-2023-46688 Open Redirect vulnerability in Pleasanter
Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.
network
low complexity
pleasanter CWE-601
6.1
2023-12-04 CVE-2023-48815 Open Redirect vulnerability in Keking Kkfileview 4.1.0/4.3.0
kkFileView v4.3.0 is vulnerable to Incorrect Access Control.
network
low complexity
keking CWE-601
6.1
2023-11-27 CVE-2023-47168 Open Redirect vulnerability in Mattermost
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=
network
low complexity
mattermost CWE-601
6.1
2023-11-21 CVE-2023-49104 Open Redirect vulnerability in Owncloud Oauth2
An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled.
network
low complexity
owncloud CWE-601
6.1
2023-11-21 CVE-2023-49061 Open Redirect vulnerability in Mozilla Firefox
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information.
network
low complexity
mozilla CWE-601
6.1