CWE-601 · 1.649 kayıt
URL Redirection to Untrusted Site ('Open Redirect')
Bu sınıftaki CVE’ler
1.652 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
58Planlayın | CVE-2017-1000117Silahlaştırılmış | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any proggit-scm · git · CWE-601 | Yüksek8,8 | — | %77,8 | 4 Eki 2017 |
55Planlayın | CVE-2021-38000Silahlaştırılmış | Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitragoogle · chrome · CWE-601 | Orta6,1 | KEV | %4,9 | 23 Kas 2021 |
50Planlayın | CVE-2021-22881Kavram kanıtı | The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability.rubyonrails · rails · CWE-601 | Orta6,1 | — | %87,3 | 11 Şub 2021 |
49Planlayın | CVE-2022-45402İstismar yok | Apache Airflow: Open redirect during loginapache · airflow · CWE-601 | Orta6,1 | — | %81,8 | 15 Kas 2022 |
49Planlayın | CVE-2012-0518Silahlaştırılmış | Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attoracle · fusion middleware · CWE-601 | Orta4,7 | KEV | %4,7 | 16 Eki 2012 |
47Planlayın | CVE-2016-5385İstismar yok | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from thp · storeever msl6480 tape library firmware · CWE-601 | Yüksek8,1 | — | %50,4 | 18 Tem 2016 |
46Planlayın | CVE-2018-11784Kavram kanıtı | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directoapache · tomcat · CWE-601 | Orta4,3 | — | %97,7 | 4 Eki 2018 |
46Planlayın | CVE-2019-10098Kavram kanıtı | In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by enapache · http server · CWE-601 | Orta6,1 | — | %74,0 | 25 Eyl 2019 |
45Planlayın | CVE-2020-8143İstismar yok | An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.revive-adserver · revive adserver · CWE-601 | Orta6,1 | — | %70,4 | 3 Nis 2020 |
45Planlayın | CVE-2021-22873Kavram kanıtı | Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delirevive-adserver · revive adserver · CWE-601 | Orta6,1 | — | %69,6 | 26 Oca 2021 |
43Planlayın | CVE-2021-28125İstismar yok | Apache Superset Open Redirectapache · superset · CWE-601 | Orta6,1 | — | %64,0 | 27 Nis 2021 |
41Planlayın | CVE-2020-1927İstismar yok | In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by enapache · http server · CWE-601 | Orta6,1 | — | %56,7 | 1 Nis 2020 |
41Planlayın | CVE-2023-32068Kavram kanıtı | URL Redirection to Untrusted Site in XWikixwiki · xwiki · CWE-601 | Orta6,1 | — | %55,1 | 15 May 2023 |
40Planlayın | CVE-2022-1058Kavram kanıtı | Open Redirect on login in go-gitea/giteagitea · gitea · CWE-601 | Orta6,1 | — | %53,2 | 24 Mar 2022 |
40Planlayın | CVE-2024-22891Kavram kanıtı | Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.nteract · nteract · CWE-601 | Kritik9,8 | — | %1,7 | 1 Mar 2024 |
39İzleyin | CVE-2022-40083Kavram kanıtı | Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component.labstack · echo · CWE-601 | Kritik9,6 | — | %3,2 | 28 Eyl 2022 |
39İzleyin | CVE-2022-31657İstismar yok | VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability.vmware · identity manager · CWE-601 | Kritik9,8 | — | %1,3 | 5 Ağu 2022 |
39İzleyin | CVE-2025-43526İstismar yok | This issue was addressed with improved URL validation.apple · safari · CWE-601 | Kritik9,8 | — | %0,5 | 17 Ara 2025 |
39İzleyin | CVE-2025-55031İstismar yok | Passkey phishing within Bluetooth rangemozilla · firefox · CWE-601 | Kritik9,8 | — | %0,4 | 19 Ağu 2025 |
38İzleyin | CVE-2025-6197Kavram kanıtı | An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.grafana · grafana · CWE-601 | Orta4,2 | — | %72,3 | 18 Tem 2025 |
38İzleyin | CVE-2017-11879İstismar yok | ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URLmicrosoft · asp.net core · CWE-601 | Yüksek8,8 | — | %9,4 | 14 Kas 2017 |
38İzleyin | CVE-2019-6741İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 samsung · galaxy s9 firmware · CWE-601 | Kritik9,3 | — | %3,2 | 3 Haz 2019 |
38İzleyin | CVE-2026-70958İstismar yok | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).oracle · hyperion infrastructure technology · CWE-601 | Kritik9,6 | — | %0,4 | 18 Ağu 2026 |
38İzleyin | CVE-2026-6795İstismar yok | Open Redirect in DivvyDrive Information Technologies' DivvyDrivedivvydrive information technologies inc. · divvydrive · CWE-601 | Kritik9,6 | — | %0,4 | 7 May 2026 |
38İzleyin | CVE-2026-23818İstismar yok | Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Premhpe · aruba networking private 5g core · CWE-601 | Kritik9,6 | — | %0,3 | 7 Nis 2026 |
- CVE-2017-100011758Planlayın
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any prog
YüksekCVSS 8,8SilahlaştırılmışEPSS %78git-scm · git4 Eki 2017
- CVE-2021-3800055Planlayın
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitra
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %5google · chrome23 Kas 2021
- CVE-2021-2288150Planlayın
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability.
OrtaCVSS 6,1Kavram kanıtıEPSS %87rubyonrails · rails11 Şub 2021
- CVE-2022-4540249Planlayın
Apache Airflow: Open redirect during login
OrtaCVSS 6,1İstismar yokEPSS %82apache · airflow15 Kas 2022
- CVE-2012-051849Planlayın
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote att
OrtaCVSS 4,7KEVSilahlaştırılmışEPSS %5oracle · fusion middleware16 Eki 2012
- CVE-2016-538547Planlayın
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t
YüksekCVSS 8,1İstismar yokEPSS %50hp · storeever msl6480 tape library firmware18 Tem 2016
- CVE-2018-1178446Planlayın
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directo
OrtaCVSS 4,3Kavram kanıtıEPSS %98apache · tomcat4 Eki 2018
- CVE-2019-1009846Planlayın
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by en
OrtaCVSS 6,1Kavram kanıtıEPSS %74apache · http server25 Eyl 2019
- CVE-2020-814345Planlayın
An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.
OrtaCVSS 6,1İstismar yokEPSS %70revive-adserver · revive adserver3 Nis 2020
- CVE-2021-2287345Planlayın
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php deli
OrtaCVSS 6,1Kavram kanıtıEPSS %70revive-adserver · revive adserver26 Oca 2021
- CVE-2021-2812543Planlayın
Apache Superset Open Redirect
OrtaCVSS 6,1İstismar yokEPSS %64apache · superset27 Nis 2021
- CVE-2020-192741Planlayın
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by en
OrtaCVSS 6,1İstismar yokEPSS %57apache · http server1 Nis 2020
- CVE-2023-3206841Planlayın
URL Redirection to Untrusted Site in XWiki
OrtaCVSS 6,1Kavram kanıtıEPSS %55xwiki · xwiki15 May 2023
- CVE-2022-105840Planlayın
Open Redirect on login in go-gitea/gitea
OrtaCVSS 6,1Kavram kanıtıEPSS %53gitea · gitea24 Mar 2022
- CVE-2024-2289140Planlayın
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
KritikCVSS 9,8Kavram kanıtıEPSS %2nteract · nteract1 Mar 2024
- CVE-2022-4008339İzleyin
Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component.
KritikCVSS 9,6Kavram kanıtıEPSS %3labstack · echo28 Eyl 2022
- CVE-2022-3165739İzleyin
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1vmware · identity manager5 Ağu 2022
- CVE-2025-4352639İzleyin
This issue was addressed with improved URL validation.
KritikCVSS 9,8İstismar yokEPSS %1apple · safari17 Ara 2025
- CVE-2025-5503139İzleyin
Passkey phishing within Bluetooth range
KritikCVSS 9,8İstismar yokEPSS %0mozilla · firefox19 Ağu 2025
- CVE-2025-619738İzleyin
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.
OrtaCVSS 4,2Kavram kanıtıEPSS %72grafana · grafana18 Tem 2025
- CVE-2017-1187938İzleyin
ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL
YüksekCVSS 8,8İstismar yokEPSS %9microsoft · asp.net core14 Kas 2017
- CVE-2019-674138İzleyin
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019
KritikCVSS 9,3İstismar yokEPSS %3samsung · galaxy s9 firmware3 Haz 2019
- CVE-2026-7095838İzleyin
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).
KritikCVSS 9,6İstismar yokEPSS %0oracle · hyperion infrastructure technology18 Ağu 2026
- CVE-2026-679538İzleyin
Open Redirect in DivvyDrive Information Technologies' DivvyDrive
KritikCVSS 9,6İstismar yokEPSS %0divvydrive information technologies inc. · divvydrive7 May 2026
- CVE-2026-2381838İzleyin
Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Prem
KritikCVSS 9,6İstismar yokEPSS %0hpe · aruba networking private 5g core7 Nis 2026