Skip to content
Noroxi

CWE-601 · 1,653 records

URL Redirection to Untrusted Site ('Open Redirect')

CVEs in this class

1,654 records

  • A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any prog

    HighCVSS 8.8WeaponizedEPSS 78%

    git-scm · gitOct 4, 2017

  • Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitra

    MediumCVSS 6.1KEVWeaponizedEPSS 5%

    google · chromeNov 23, 2021

  • The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability.

    MediumCVSS 6.1Proof of conceptEPSS 87%

    rubyonrails · railsFeb 11, 2021

  • Apache Airflow: Open redirect during login

    MediumCVSS 6.1No exploitEPSS 82%

    apache · airflowNov 15, 2022

  • Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote att

    MediumCVSS 4.7KEVWeaponizedEPSS 5%

    oracle · fusion middlewareOct 16, 2012

  • PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t

    HighCVSS 8.1No exploitEPSS 50%

    hp · storeever msl6480 tape library firmwareJul 18, 2016

  • When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directo

    MediumCVSS 4.3Proof of conceptEPSS 98%

    apache · tomcatOct 4, 2018

  • In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by en

    MediumCVSS 6.1Proof of conceptEPSS 74%

    apache · http serverSep 25, 2019

  • An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.

    MediumCVSS 6.1No exploitEPSS 70%

    revive-adserver · revive adserverApr 3, 2020

  • Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php deli

    MediumCVSS 6.1Proof of conceptEPSS 70%

    revive-adserver · revive adserverJan 26, 2021

  • Apache Superset Open Redirect

    MediumCVSS 6.1No exploitEPSS 64%

    apache · supersetApr 27, 2021

  • In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by en

    MediumCVSS 6.1No exploitEPSS 57%

    apache · http serverApr 1, 2020

  • URL Redirection to Untrusted Site in XWiki

    MediumCVSS 6.1Proof of conceptEPSS 55%

    xwiki · xwikiMay 15, 2023

  • Open Redirect on login in go-gitea/gitea

    MediumCVSS 6.1Proof of conceptEPSS 53%

    gitea · giteaMar 24, 2022

  • Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    nteract · nteractMar 1, 2024

  • Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component.

    CriticalCVSS 9.6Proof of conceptEPSS 3%

    labstack · echoSep 28, 2022

  • VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    vmware · identity managerAug 5, 2022

  • This issue was addressed with improved URL validation.

    CriticalCVSS 9.8No exploitEPSS 1%

    apple · safariDec 17, 2025

  • Passkey phishing within Bluetooth range

    CriticalCVSS 9.8No exploitEPSS 0%

    mozilla · firefoxAug 19, 2025

  • CVE-2025-6197
    38Monitor

    An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.

    MediumCVSS 4.2Proof of conceptEPSS 72%

    grafana · grafanaJul 18, 2025

  • ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL

    HighCVSS 8.8No exploitEPSS 9%

    microsoft · asp.net coreNov 14, 2017

  • CVE-2019-6741
    38Monitor

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019

    CriticalCVSS 9.3No exploitEPSS 3%

    samsung · galaxy s9 firmwareJun 3, 2019

  • Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).

    CriticalCVSS 9.6No exploitEPSS 0%

    oracle · hyperion infrastructure technologyAug 18, 2026

  • CVE-2026-6795
    38Monitor

    Open Redirect in DivvyDrive Information Technologies' DivvyDrive

    CriticalCVSS 9.6No exploitEPSS 0%

    divvydrive information technologies inc. · divvydriveMay 7, 2026

  • Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Prem

    CriticalCVSS 9.6No exploitEPSS 0%

    hpe · aruba networking private 5g coreApr 7, 2026

All vulnerability classes