CWE-601 · 1,653 records
URL Redirection to Untrusted Site ('Open Redirect')
CVEs in this class
1,654 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2017-1000117Weaponized | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any proggit-scm · git · CWE-601 | High8.8 | — | 77.8% | Oct 4, 2017 |
55Plan | CVE-2021-38000Weaponized | Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitragoogle · chrome · CWE-601 | Medium6.1 | KEV | 4.9% | Nov 23, 2021 |
50Plan | CVE-2021-22881Proof of concept | The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability.rubyonrails · rails · CWE-601 | Medium6.1 | — | 87.3% | Feb 11, 2021 |
49Plan | CVE-2022-45402No exploit | Apache Airflow: Open redirect during loginapache · airflow · CWE-601 | Medium6.1 | — | 81.8% | Nov 15, 2022 |
49Plan | CVE-2012-0518Weaponized | Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attoracle · fusion middleware · CWE-601 | Medium4.7 | KEV | 4.7% | Oct 16, 2012 |
47Plan | CVE-2016-5385No exploit | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from thp · storeever msl6480 tape library firmware · CWE-601 | High8.1 | — | 50.4% | Jul 18, 2016 |
46Plan | CVE-2018-11784Proof of concept | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directoapache · tomcat · CWE-601 | Medium4.3 | — | 97.7% | Oct 4, 2018 |
46Plan | CVE-2019-10098Proof of concept | In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by enapache · http server · CWE-601 | Medium6.1 | — | 74.0% | Sep 25, 2019 |
45Plan | CVE-2020-8143No exploit | An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.revive-adserver · revive adserver · CWE-601 | Medium6.1 | — | 70.4% | Apr 3, 2020 |
45Plan | CVE-2021-22873Proof of concept | Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delirevive-adserver · revive adserver · CWE-601 | Medium6.1 | — | 69.6% | Jan 26, 2021 |
43Plan | CVE-2021-28125No exploit | Apache Superset Open Redirectapache · superset · CWE-601 | Medium6.1 | — | 64.0% | Apr 27, 2021 |
41Plan | CVE-2020-1927No exploit | In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by enapache · http server · CWE-601 | Medium6.1 | — | 56.7% | Apr 1, 2020 |
41Plan | CVE-2023-32068Proof of concept | URL Redirection to Untrusted Site in XWikixwiki · xwiki · CWE-601 | Medium6.1 | — | 55.1% | May 15, 2023 |
40Plan | CVE-2022-1058Proof of concept | Open Redirect on login in go-gitea/giteagitea · gitea · CWE-601 | Medium6.1 | — | 53.2% | Mar 24, 2022 |
40Plan | CVE-2024-22891Proof of concept | Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.nteract · nteract · CWE-601 | Critical9.8 | — | 1.7% | Mar 1, 2024 |
39Monitor | CVE-2022-40083Proof of concept | Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component.labstack · echo · CWE-601 | Critical9.6 | — | 3.2% | Sep 28, 2022 |
39Monitor | CVE-2022-31657No exploit | VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability.vmware · identity manager · CWE-601 | Critical9.8 | — | 1.4% | Aug 5, 2022 |
39Monitor | CVE-2025-43526No exploit | This issue was addressed with improved URL validation.apple · safari · CWE-601 | Critical9.8 | — | 0.5% | Dec 17, 2025 |
39Monitor | CVE-2025-55031No exploit | Passkey phishing within Bluetooth rangemozilla · firefox · CWE-601 | Critical9.8 | — | 0.4% | Aug 19, 2025 |
38Monitor | CVE-2025-6197Proof of concept | An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.grafana · grafana · CWE-601 | Medium4.2 | — | 72.3% | Jul 18, 2025 |
38Monitor | CVE-2017-11879No exploit | ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URLmicrosoft · asp.net core · CWE-601 | High8.8 | — | 9.4% | Nov 14, 2017 |
38Monitor | CVE-2019-6741No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 samsung · galaxy s9 firmware · CWE-601 | Critical9.3 | — | 3.2% | Jun 3, 2019 |
38Monitor | CVE-2026-70958No exploit | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).oracle · hyperion infrastructure technology · CWE-601 | Critical9.6 | — | 0.4% | Aug 18, 2026 |
38Monitor | CVE-2026-6795No exploit | Open Redirect in DivvyDrive Information Technologies' DivvyDrivedivvydrive information technologies inc. · divvydrive · CWE-601 | Critical9.6 | — | 0.4% | May 7, 2026 |
38Monitor | CVE-2026-23818No exploit | Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Premhpe · aruba networking private 5g core · CWE-601 | Critical9.6 | — | 0.3% | Apr 7, 2026 |
- CVE-2017-100011758Plan
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any prog
HighCVSS 8.8WeaponizedEPSS 78%git-scm · gitOct 4, 2017
- CVE-2021-3800055Plan
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitra
MediumCVSS 6.1KEVWeaponizedEPSS 5%google · chromeNov 23, 2021
- CVE-2021-2288150Plan
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability.
MediumCVSS 6.1Proof of conceptEPSS 87%rubyonrails · railsFeb 11, 2021
- CVE-2022-4540249Plan
Apache Airflow: Open redirect during login
MediumCVSS 6.1No exploitEPSS 82%apache · airflowNov 15, 2022
- CVE-2012-051849Plan
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote att
MediumCVSS 4.7KEVWeaponizedEPSS 5%oracle · fusion middlewareOct 16, 2012
- CVE-2016-538547Plan
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t
HighCVSS 8.1No exploitEPSS 50%hp · storeever msl6480 tape library firmwareJul 18, 2016
- CVE-2018-1178446Plan
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directo
MediumCVSS 4.3Proof of conceptEPSS 98%apache · tomcatOct 4, 2018
- CVE-2019-1009846Plan
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by en
MediumCVSS 6.1Proof of conceptEPSS 74%apache · http serverSep 25, 2019
- CVE-2020-814345Plan
An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.
MediumCVSS 6.1No exploitEPSS 70%revive-adserver · revive adserverApr 3, 2020
- CVE-2021-2287345Plan
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php deli
MediumCVSS 6.1Proof of conceptEPSS 70%revive-adserver · revive adserverJan 26, 2021
- CVE-2021-2812543Plan
Apache Superset Open Redirect
MediumCVSS 6.1No exploitEPSS 64%apache · supersetApr 27, 2021
- CVE-2020-192741Plan
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by en
MediumCVSS 6.1No exploitEPSS 57%apache · http serverApr 1, 2020
- CVE-2023-3206841Plan
URL Redirection to Untrusted Site in XWiki
MediumCVSS 6.1Proof of conceptEPSS 55%xwiki · xwikiMay 15, 2023
- CVE-2022-105840Plan
Open Redirect on login in go-gitea/gitea
MediumCVSS 6.1Proof of conceptEPSS 53%gitea · giteaMar 24, 2022
- CVE-2024-2289140Plan
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
CriticalCVSS 9.8Proof of conceptEPSS 2%nteract · nteractMar 1, 2024
- CVE-2022-4008339Monitor
Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component.
CriticalCVSS 9.6Proof of conceptEPSS 3%labstack · echoSep 28, 2022
- CVE-2022-3165739Monitor
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%vmware · identity managerAug 5, 2022
- CVE-2025-4352639Monitor
This issue was addressed with improved URL validation.
CriticalCVSS 9.8No exploitEPSS 1%apple · safariDec 17, 2025
- CVE-2025-5503139Monitor
Passkey phishing within Bluetooth range
CriticalCVSS 9.8No exploitEPSS 0%mozilla · firefoxAug 19, 2025
- CVE-2025-619738Monitor
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.
MediumCVSS 4.2Proof of conceptEPSS 72%grafana · grafanaJul 18, 2025
- CVE-2017-1187938Monitor
ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL
HighCVSS 8.8No exploitEPSS 9%microsoft · asp.net coreNov 14, 2017
- CVE-2019-674138Monitor
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019
CriticalCVSS 9.3No exploitEPSS 3%samsung · galaxy s9 firmwareJun 3, 2019
- CVE-2026-7095838Monitor
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).
CriticalCVSS 9.6No exploitEPSS 0%oracle · hyperion infrastructure technologyAug 18, 2026
- CVE-2026-679538Monitor
Open Redirect in DivvyDrive Information Technologies' DivvyDrive
CriticalCVSS 9.6No exploitEPSS 0%divvydrive information technologies inc. · divvydriveMay 7, 2026
- CVE-2026-2381838Monitor
Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Prem
CriticalCVSS 9.6No exploitEPSS 0%hpe · aruba networking private 5g coreApr 7, 2026