CWE-601 · 1 649 записей
URL Redirection to Untrusted Site ('Open Redirect')
CVE этого класса
1 652 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2017-1000117Готовый эксплойт | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any proggit-scm · git · CWE-601 | Высокая8,8 | — | 77,8 % | 4 окт. 2017 г. |
55В плане | CVE-2021-38000Готовый эксплойт | Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitragoogle · chrome · CWE-601 | Средняя6,1 | KEV | 4,9 % | 23 нояб. 2021 г. |
50В плане | CVE-2021-22881Proof of concept | The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability.rubyonrails · rails · CWE-601 | Средняя6,1 | — | 87,3 % | 11 февр. 2021 г. |
49В плане | CVE-2022-45402Эксплойта нет | Apache Airflow: Open redirect during loginapache · airflow · CWE-601 | Средняя6,1 | — | 81,8 % | 15 нояб. 2022 г. |
49В плане | CVE-2012-0518Готовый эксплойт | Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attoracle · fusion middleware · CWE-601 | Средняя4,7 | KEV | 4,7 % | 16 окт. 2012 г. |
47В плане | CVE-2016-5385Эксплойта нет | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from thp · storeever msl6480 tape library firmware · CWE-601 | Высокая8,1 | — | 50,4 % | 18 июл. 2016 г. |
46В плане | CVE-2018-11784Proof of concept | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directoapache · tomcat · CWE-601 | Средняя4,3 | — | 97,7 % | 4 окт. 2018 г. |
46В плане | CVE-2019-10098Proof of concept | In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by enapache · http server · CWE-601 | Средняя6,1 | — | 74,0 % | 25 сент. 2019 г. |
45В плане | CVE-2020-8143Эксплойта нет | An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.revive-adserver · revive adserver · CWE-601 | Средняя6,1 | — | 70,4 % | 3 апр. 2020 г. |
45В плане | CVE-2021-22873Proof of concept | Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delirevive-adserver · revive adserver · CWE-601 | Средняя6,1 | — | 69,6 % | 26 янв. 2021 г. |
43В плане | CVE-2021-28125Эксплойта нет | Apache Superset Open Redirectapache · superset · CWE-601 | Средняя6,1 | — | 64,0 % | 27 апр. 2021 г. |
41В плане | CVE-2020-1927Эксплойта нет | In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by enapache · http server · CWE-601 | Средняя6,1 | — | 56,7 % | 1 апр. 2020 г. |
41В плане | CVE-2023-32068Proof of concept | URL Redirection to Untrusted Site in XWikixwiki · xwiki · CWE-601 | Средняя6,1 | — | 55,1 % | 15 мая 2023 г. |
40В плане | CVE-2022-1058Proof of concept | Open Redirect on login in go-gitea/giteagitea · gitea · CWE-601 | Средняя6,1 | — | 53,2 % | 24 мар. 2022 г. |
40В плане | CVE-2024-22891Proof of concept | Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.nteract · nteract · CWE-601 | Критическая9,8 | — | 1,7 % | 1 мар. 2024 г. |
39Наблюдать | CVE-2022-40083Proof of concept | Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component.labstack · echo · CWE-601 | Критическая9,6 | — | 3,2 % | 28 сент. 2022 г. |
39Наблюдать | CVE-2022-31657Эксплойта нет | VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability.vmware · identity manager · CWE-601 | Критическая9,8 | — | 1,3 % | 5 авг. 2022 г. |
39Наблюдать | CVE-2025-43526Эксплойта нет | This issue was addressed with improved URL validation.apple · safari · CWE-601 | Критическая9,8 | — | 0,5 % | 17 дек. 2025 г. |
39Наблюдать | CVE-2025-55031Эксплойта нет | Passkey phishing within Bluetooth rangemozilla · firefox · CWE-601 | Критическая9,8 | — | 0,4 % | 19 авг. 2025 г. |
38Наблюдать | CVE-2025-6197Proof of concept | An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.grafana · grafana · CWE-601 | Средняя4,2 | — | 72,3 % | 18 июл. 2025 г. |
38Наблюдать | CVE-2017-11879Эксплойта нет | ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URLmicrosoft · asp.net core · CWE-601 | Высокая8,8 | — | 9,4 % | 14 нояб. 2017 г. |
38Наблюдать | CVE-2019-6741Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 samsung · galaxy s9 firmware · CWE-601 | Критическая9,3 | — | 3,2 % | 3 июн. 2019 г. |
38Наблюдать | CVE-2026-70958Эксплойта нет | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).oracle · hyperion infrastructure technology · CWE-601 | Критическая9,6 | — | 0,4 % | 18 авг. 2026 г. |
38Наблюдать | CVE-2026-6795Эксплойта нет | Open Redirect in DivvyDrive Information Technologies' DivvyDrivedivvydrive information technologies inc. · divvydrive · CWE-601 | Критическая9,6 | — | 0,4 % | 7 мая 2026 г. |
38Наблюдать | CVE-2026-23818Эксплойта нет | Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Premhpe · aruba networking private 5g core · CWE-601 | Критическая9,6 | — | 0,3 % | 7 апр. 2026 г. |
- CVE-2017-100011758В плане
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any prog
ВысокаяCVSS 8,8Готовый эксплойтEPSS 78 %git-scm · git4 окт. 2017 г.
- CVE-2021-3800055В плане
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitra
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 5 %google · chrome23 нояб. 2021 г.
- CVE-2021-2288150В плане
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability.
СредняяCVSS 6,1Proof of conceptEPSS 87 %rubyonrails · rails11 февр. 2021 г.
- CVE-2022-4540249В плане
Apache Airflow: Open redirect during login
СредняяCVSS 6,1Эксплойта нетEPSS 82 %apache · airflow15 нояб. 2022 г.
- CVE-2012-051849В плане
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote att
СредняяCVSS 4,7KEVГотовый эксплойтEPSS 5 %oracle · fusion middleware16 окт. 2012 г.
- CVE-2016-538547В плане
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t
ВысокаяCVSS 8,1Эксплойта нетEPSS 50 %hp · storeever msl6480 tape library firmware18 июл. 2016 г.
- CVE-2018-1178446В плане
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directo
СредняяCVSS 4,3Proof of conceptEPSS 98 %apache · tomcat4 окт. 2018 г.
- CVE-2019-1009846В плане
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by en
СредняяCVSS 6,1Proof of conceptEPSS 74 %apache · http server25 сент. 2019 г.
- CVE-2020-814345В плане
An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.
СредняяCVSS 6,1Эксплойта нетEPSS 70 %revive-adserver · revive adserver3 апр. 2020 г.
- CVE-2021-2287345В плане
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php deli
СредняяCVSS 6,1Proof of conceptEPSS 70 %revive-adserver · revive adserver26 янв. 2021 г.
- CVE-2021-2812543В плане
Apache Superset Open Redirect
СредняяCVSS 6,1Эксплойта нетEPSS 64 %apache · superset27 апр. 2021 г.
- CVE-2020-192741В плане
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by en
СредняяCVSS 6,1Эксплойта нетEPSS 57 %apache · http server1 апр. 2020 г.
- CVE-2023-3206841В плане
URL Redirection to Untrusted Site in XWiki
СредняяCVSS 6,1Proof of conceptEPSS 55 %xwiki · xwiki15 мая 2023 г.
- CVE-2022-105840В плане
Open Redirect on login in go-gitea/gitea
СредняяCVSS 6,1Proof of conceptEPSS 53 %gitea · gitea24 мар. 2022 г.
- CVE-2024-2289140В плане
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
КритическаяCVSS 9,8Proof of conceptEPSS 2 %nteract · nteract1 мар. 2024 г.
- CVE-2022-4008339Наблюдать
Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component.
КритическаяCVSS 9,6Proof of conceptEPSS 3 %labstack · echo28 сент. 2022 г.
- CVE-2022-3165739Наблюдать
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vmware · identity manager5 авг. 2022 г.
- CVE-2025-4352639Наблюдать
This issue was addressed with improved URL validation.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apple · safari17 дек. 2025 г.
- CVE-2025-5503139Наблюдать
Passkey phishing within Bluetooth range
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %mozilla · firefox19 авг. 2025 г.
- CVE-2025-619738Наблюдать
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.
СредняяCVSS 4,2Proof of conceptEPSS 72 %grafana · grafana18 июл. 2025 г.
- CVE-2017-1187938Наблюдать
ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL
ВысокаяCVSS 8,8Эксплойта нетEPSS 9 %microsoft · asp.net core14 нояб. 2017 г.
- CVE-2019-674138Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %samsung · galaxy s9 firmware3 июн. 2019 г.
- CVE-2026-7095838Наблюдать
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %oracle · hyperion infrastructure technology18 авг. 2026 г.
- CVE-2026-679538Наблюдать
Open Redirect in DivvyDrive Information Technologies' DivvyDrive
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %divvydrive information technologies inc. · divvydrive7 мая 2026 г.
- CVE-2026-2381838Наблюдать
Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Prem
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %hpe · aruba networking private 5g core7 апр. 2026 г.