Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-47070 |
|
Open Redirect in hackney (CVE-2026-47070)
vulnerability in hackney (CVE-2026-47070). Risk of unauthorized operations or information disclosure. Exploitable via ``Authorization``. Mitigation: upgrade to `4.0.1` or later.
|
| CVE-2026-46616 |
|
Open Redirect in Umbraco.Cms (CVE-2026-46616)
vulnerability in Umbraco.Cms (CVE-2026-46616). Risk of unauthorized operations or information disclosure. Exploitable via ``UmbLoginStatusController``. Mitigation: upgrade to `17.4.0` or later.
|
| CVE-2026-2813 |
|
Open Redirect in esri (CVE-2026-2813)
vulnerability in esri (CVE-2026-2813). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7504 |
|
Open Redirect in org.keycloak:keycloak-services (CVE-2026-7504)
vulnerability in org.keycloak:keycloak-services (CVE-2026-7504). Confidential information can be exposed externally. Mitigation: upgrade to `26.6.2` or later.
|
| CVE-2026-45037 |
|
Vulnerability in tabby (CVE-2026-45037)
vulnerability in tabby (CVE-2026-45037). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.232` or later.
|
| CVE-2026-42207 |
|
Open Redirect in openmage/magento-lts (CVE-2026-42207)
vulnerability in openmage/magento-lts (CVE-2026-42207). Risk of unauthorized operations or information disclosure. Exploitable via `GET /productalert/add/stock/`. Mitigation: upgrade to `20.18.0` or later.
|
| CVE-2025-65954 |
|
Open Redirect in simplesamlphp/simplesamlphp-module-casserver (CVE-2025-65954)
vulnerability in simplesamlphp/simplesamlphp-module-casserver (CVE-2025-65954). Risk of unauthorized operations or information disclosure. Exploitable via ``url``. Mitigation: upgrade to `6.3.1` or later.
|
| CVE-2026-44520 |
|
Open Redirect in docling-graph (CVE-2026-44520)
vulnerability in docling-graph (CVE-2026-44520). Confidential information can be exposed externally. Exploitable via ``URLInputHandler``. Mitigation: upgrade to `1.5.1` or later.
|
| CVE-2026-45448 |
|
CWE-601 URL redirection to untrusted site ('open redirect')
CWE-601 URL redirection to untrusted site ('open redirect')
|
| CVE-2026-44503 |
|
Open Redirect in com.microsoft.kiota:microsoft-kiota-abstractions (CVE-2026-44503)
vulnerability in com.microsoft.kiota:microsoft-kiota-abstractions (CVE-2026-44503). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-44437 |
|
Path Traversal in @angular/ssr (CVE-2026-44437)
path traversal in @angular/ssr (CVE-2026-44437). Risk of unauthorized operations or information disclosure. Exploitable via ``redirectTo``. Mitigation: upgrade to `19.2.25` or later.
|
| CVE-2026-45055 |
|
Vulnerability in CVE-2026-45055 (CVE-2026-45055)
vulnerability in CVE-2026-45055 (CVE-2026-45055). Confidential information can be exposed externally. Exploitable via `POST /index.php`. Mitigation: upgrade to `6.7.2` or later.
|
| CVE-2026-44372 |
|
Open Redirect in nitro (CVE-2026-44372)
vulnerability in nitro (CVE-2026-44372). Risk of unauthorized operations or information disclosure. Exploitable via `GET /legacy//evil.com`. Mitigation: upgrade to `3.0.260429-beta` or later.
|
| CVE-2026-44681 |
|
Open Redirect in authlib (CVE-2026-44681)
vulnerability in authlib (CVE-2026-44681). Risk of unauthorized operations or information disclosure. Exploitable via `GET /oauth/authorize`. Mitigation: upgrade to `3be08468` or later.
|
| CVE-2026-41513 |
|
Open Redirect in CVE-2026-41513 (CVE-2026-41513)
vulnerability in CVE-2026-41513 (CVE-2026-41513). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42565 |
|
Open Redirect in @workos/authkit-session (CVE-2026-42565)
vulnerability in @workos/authkit-session (CVE-2026-42565). Risk of unauthorized operations or information disclosure. Exploitable via ``AuthService.handleCallback``. Mitigation: upgrade to `0.5.1` or later.
|
| CVE-2026-44833 |
|
Open Redirect in snipe/snipe-it (CVE-2026-44833)
vulnerability in snipe/snipe-it (CVE-2026-44833). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `8.4.1` or later.
|
| CVE-2026-42350 |
|
Open Redirect in github.com/akuity/kargo (CVE-2026-42350)
vulnerability in github.com/akuity/kargo (CVE-2026-42350). Risk of unauthorized operations or information disclosure. Exploitable via ``redirectTo``. Mitigation: upgrade to `1.10.2` or later.
|
| CVE-2026-42195 |
|
Information Disclosure in CVE-2026-42195 (CVE-2026-42195)
vulnerability in CVE-2026-42195 (CVE-2026-42195). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44427 |
|
Open Redirect in github.com/modelcontextprotocol/registry (CVE-2026-44427)
vulnerability in github.com/modelcontextprotocol/registry (CVE-2026-44427). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.5` or later.
|
| CVE-2026-40295 |
|
Open Redirect in devise (CVE-2026-40295)
vulnerability in devise (CVE-2026-40295). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `5.0.4` or later.
|
| CVE-2026-3318 |
|
Open Redirect in CVE-2026-3318 (CVE-2026-3318)
vulnerability in CVE-2026-3318 (CVE-2026-3318). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43941 |
|
Vulnerability in electerm (CVE-2026-43941)
vulnerability in electerm (CVE-2026-43941). Successful exploitation can lead to full system takeover. Exploitable via ``shell.openExternal``.
|
| CVE-2026-42259 |
|
Open Redirect in @saltcorn/server (CVE-2026-42259)
vulnerability in @saltcorn/server (CVE-2026-42259). Risk of unauthorized operations or information disclosure. Exploitable via ``dest``. Mitigation: upgrade to `1.6.0-beta.5` or later.
|
| CVE-2026-35253 |
|
Open Redirect in oracle (CVE-2026-35253)
vulnerability in oracle (CVE-2026-35253). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61669 |
|
Open Redirect in jupyter-server (CVE-2025-61669)
vulnerability in jupyter-server (CVE-2025-61669). Risk of unauthorized operations or information disclosure. Exploitable via ``google.com``. Mitigation: upgrade to `2.18.0` or later.
|
| CVE-2026-34257 |
|
Open Redirect in sap (CVE-2026-34257)
vulnerability in sap (CVE-2026-34257). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40037 |
|
Open Redirect in openclaw (CVE-2026-40037)
vulnerability in openclaw (CVE-2026-40037). Confidential information can be exposed externally. Mitigation: upgrade to `2026.4.8` or later.
|
| CVE-2026-39484 |
|
Open Redirect in CVE-2026-39484 (CVE-2026-39484)
vulnerability in CVE-2026-39484 (CVE-2026-39484). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35473 |
|
Open Redirect in wegia (CVE-2026-35473)
vulnerability in wegia (CVE-2026-35473). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
|
| CVE-2026-35474 |
|
Open Redirect in wegia (CVE-2026-35474)
vulnerability in wegia (CVE-2026-35474). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
|
| CVE-2026-35475 |
|
Open Redirect in wegia (CVE-2026-35475)
vulnerability in wegia (CVE-2026-35475). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
|
| CVE-2026-35410 |
|
Vulnerability in monospace (CVE-2026-35410)
vulnerability in monospace (CVE-2026-35410). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.16.1` or later.
|
| CVE-2026-35411 |
|
Open Redirect in monospace (CVE-2026-35411)
vulnerability in monospace (CVE-2026-35411). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.16.1` or later.
|
| CVE-2026-35404 |
|
Open Redirect in openedx (CVE-2026-35404)
vulnerability in openedx (CVE-2026-35404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35472 |
|
Open Redirect in wegia (CVE-2026-35472)
vulnerability in wegia (CVE-2026-35472). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
|
| CVE-2026-35396 |
|
Open Redirect in wegia (CVE-2026-35396)
vulnerability in wegia (CVE-2026-35396). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
|
| CVE-2026-35398 |
|
Open Redirect in wegia (CVE-2026-35398)
vulnerability in wegia (CVE-2026-35398). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
|
| CVE-2018-25245 |
|
Open Redirect in dos (CVE-2018-25245)
vulnerability in dos (CVE-2018-25245). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33709 |
|
Open Redirect in jupyter (CVE-2026-33709)
vulnerability in jupyter (CVE-2026-33709). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5467 |
|
Open Redirect in github.com/casdoor/casdoor (CVE-2026-5467)
vulnerability in github.com/casdoor/casdoor (CVE-2026-5467). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34847 |
|
Open Redirect in hoppscotch (CVE-2026-34847)
vulnerability in hoppscotch (CVE-2026-34847). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34931 |
|
Open Redirect in hoppscotch (CVE-2026-34931)
vulnerability in hoppscotch (CVE-2026-34931). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34083 |
|
Vulnerability in signalk (CVE-2026-34083)
vulnerability in signalk (CVE-2026-34083). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-3872 |
|
Open Redirect in redhat (CVE-2026-3872)
vulnerability in redhat (CVE-2026-3872). Confidential information can be exposed externally.
|
| CVE-2026-34442 |
|
Vulnerability in laravel (CVE-2026-34442)
vulnerability in laravel (CVE-2026-34442). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-32113 |
|
Open Redirect in discourse (CVE-2026-32113)
vulnerability in discourse (CVE-2026-32113). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4799 |
|
Open Redirect in search-guard (CVE-2026-4799)
vulnerability in search-guard (CVE-2026-4799). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1166 |
|
Open Redirect in hitachi (CVE-2026-1166)
vulnerability in hitachi (CVE-2026-1166). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20994 |
|
Open Redirect in samsung (CVE-2026-20994)
vulnerability in samsung (CVE-2026-20994). Risk of unauthorized operations or information disclosure.
|