Vulnerabilities (CVE)

Filtered by CWE-601
Total 966 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-5969 1 Weseek 1 Growi 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.
CVE-2019-0540 1 Microsoft 5 Excel Viewer, Office, Office 365 Proplus and 2 more 2024-02-04 4.3 MEDIUM 5.5 MEDIUM
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
CVE-2019-3850 1 Moodle 1 Moodle 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.
CVE-2019-1010290 1 Cmsmadesimple 1 Bable\ 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker. Attacker may use any legitimate site using Babel to redirect user to a URL of his/her choosing.
CVE-2019-15774 1 Booking Project 1 Booking 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
CVE-2019-5823 4 Debian, Fedoraproject, Google and 1 more 5 Debian Linux, Fedora, Chrome and 2 more 2024-02-04 5.8 MEDIUM 5.4 MEDIUM
Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2019-6004 1 Fujixerox 2 Apeosware Management Suite, Apeosware Management Suite 2 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2019-10372 1 Jenkins 1 Gitlab Oauth 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.
CVE-2019-15772 1 Donations Project 1 Donations 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
CVE-2019-1020016 1 Ash-aio Project 1 Ash-aio 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
ASH-AIO before 2.0.0.3 allows an open redirect.
CVE-2019-9915 1 Get-simple. 1 Getsimplecms 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
CVE-2019-15775 1 Learning Courses Project 1 Learning Courses 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
CVE-2019-10955 1 Rockwellautomation 11 Compactlogix 5370 L1, Compactlogix 5370 L1 Firmware, Compactlogix 5370 L2 and 8 more 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier, an open redirect vulnerability could allow a remote unauthenticated attacker to input a malicious link to redirect users to a malicious site that could run or download arbitrary malware on the user’s machine.
CVE-2019-13175 1 Readthedocs 1 Read The Docs 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addition to the public readthedocs.org web sites).
CVE-2019-10117 1 Gitlab 1 Gitlab 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.
CVE-2019-10133 1 Moodle 1 Moodle 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
CVE-2018-5548 1 F5 1 Big-ip Access Policy Manager 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts.
CVE-2018-12675 1 Sv3c 4 H.264 Poe Ip Camera Firmware, Sv-b01poe-1080p-l, Sv-b11vpoe-1080p-l and 1 more 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpected endpoint.
CVE-2013-0594 1 Ibm 1 Inotes 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383.
CVE-2018-15493 1 Vbulletin 1 Vbulletin 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
vBulletin 5.4.3 has an Open Redirect.