Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-601 Clear
ID Title
CVE-2026-47070 Open Redirect in hackney (CVE-2026-47070)
vulnerability in hackney (CVE-2026-47070). Risk of unauthorized operations or information disclosure. Exploitable via ``Authorization``. Mitigation: upgrade to `4.0.1` or later.
CVE-2026-46616 Open Redirect in Umbraco.Cms (CVE-2026-46616)
vulnerability in Umbraco.Cms (CVE-2026-46616). Risk of unauthorized operations or information disclosure. Exploitable via ``UmbLoginStatusController``. Mitigation: upgrade to `17.4.0` or later.
CVE-2026-2813 Open Redirect in esri (CVE-2026-2813)
vulnerability in esri (CVE-2026-2813). Risk of unauthorized operations or information disclosure.
CVE-2026-7504 Open Redirect in org.keycloak:keycloak-services (CVE-2026-7504)
vulnerability in org.keycloak:keycloak-services (CVE-2026-7504). Confidential information can be exposed externally. Mitigation: upgrade to `26.6.2` or later.
CVE-2026-45037 Vulnerability in tabby (CVE-2026-45037)
vulnerability in tabby (CVE-2026-45037). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.232` or later.
CVE-2026-42207 Open Redirect in openmage/magento-lts (CVE-2026-42207)
vulnerability in openmage/magento-lts (CVE-2026-42207). Risk of unauthorized operations or information disclosure. Exploitable via `GET /productalert/add/stock/`. Mitigation: upgrade to `20.18.0` or later.
CVE-2025-65954 Open Redirect in simplesamlphp/simplesamlphp-module-casserver (CVE-2025-65954)
vulnerability in simplesamlphp/simplesamlphp-module-casserver (CVE-2025-65954). Risk of unauthorized operations or information disclosure. Exploitable via ``url``. Mitigation: upgrade to `6.3.1` or later.
CVE-2026-44520 Open Redirect in docling-graph (CVE-2026-44520)
vulnerability in docling-graph (CVE-2026-44520). Confidential information can be exposed externally. Exploitable via ``URLInputHandler``. Mitigation: upgrade to `1.5.1` or later.
CVE-2026-45448 CWE-601 URL redirection to untrusted site ('open redirect')
CWE-601 URL redirection to untrusted site ('open redirect')
CVE-2026-44503 Open Redirect in com.microsoft.kiota:microsoft-kiota-abstractions (CVE-2026-44503)
vulnerability in com.microsoft.kiota:microsoft-kiota-abstractions (CVE-2026-44503). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `1.9.1` or later.
CVE-2026-44437 Path Traversal in @angular/ssr (CVE-2026-44437)
path traversal in @angular/ssr (CVE-2026-44437). Risk of unauthorized operations or information disclosure. Exploitable via ``redirectTo``. Mitigation: upgrade to `19.2.25` or later.
CVE-2026-45055 Vulnerability in CVE-2026-45055 (CVE-2026-45055)
vulnerability in CVE-2026-45055 (CVE-2026-45055). Confidential information can be exposed externally. Exploitable via `POST /index.php`. Mitigation: upgrade to `6.7.2` or later.
CVE-2026-44372 Open Redirect in nitro (CVE-2026-44372)
vulnerability in nitro (CVE-2026-44372). Risk of unauthorized operations or information disclosure. Exploitable via `GET /legacy//evil.com`. Mitigation: upgrade to `3.0.260429-beta` or later.
CVE-2026-44681 Open Redirect in authlib (CVE-2026-44681)
vulnerability in authlib (CVE-2026-44681). Risk of unauthorized operations or information disclosure. Exploitable via `GET /oauth/authorize`. Mitigation: upgrade to `3be08468` or later.
CVE-2026-41513 Open Redirect in CVE-2026-41513 (CVE-2026-41513)
vulnerability in CVE-2026-41513 (CVE-2026-41513). Risk of unauthorized operations or information disclosure.
CVE-2026-42565 Open Redirect in @workos/authkit-session (CVE-2026-42565)
vulnerability in @workos/authkit-session (CVE-2026-42565). Risk of unauthorized operations or information disclosure. Exploitable via ``AuthService.handleCallback``. Mitigation: upgrade to `0.5.1` or later.
CVE-2026-44833 Open Redirect in snipe/snipe-it (CVE-2026-44833)
vulnerability in snipe/snipe-it (CVE-2026-44833). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `8.4.1` or later.
CVE-2026-42350 Open Redirect in github.com/akuity/kargo (CVE-2026-42350)
vulnerability in github.com/akuity/kargo (CVE-2026-42350). Risk of unauthorized operations or information disclosure. Exploitable via ``redirectTo``. Mitigation: upgrade to `1.10.2` or later.
CVE-2026-42195 Information Disclosure in CVE-2026-42195 (CVE-2026-42195)
vulnerability in CVE-2026-42195 (CVE-2026-42195). Risk of unauthorized operations or information disclosure.
CVE-2026-44427 Open Redirect in github.com/modelcontextprotocol/registry (CVE-2026-44427)
vulnerability in github.com/modelcontextprotocol/registry (CVE-2026-44427). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.5` or later.
CVE-2026-40295 Open Redirect in devise (CVE-2026-40295)
vulnerability in devise (CVE-2026-40295). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `5.0.4` or later.
CVE-2026-3318 Open Redirect in CVE-2026-3318 (CVE-2026-3318)
vulnerability in CVE-2026-3318 (CVE-2026-3318). Risk of unauthorized operations or information disclosure.
CVE-2026-43941 Vulnerability in electerm (CVE-2026-43941)
vulnerability in electerm (CVE-2026-43941). Successful exploitation can lead to full system takeover. Exploitable via ``shell.openExternal``.
CVE-2026-42259 Open Redirect in @saltcorn/server (CVE-2026-42259)
vulnerability in @saltcorn/server (CVE-2026-42259). Risk of unauthorized operations or information disclosure. Exploitable via ``dest``. Mitigation: upgrade to `1.6.0-beta.5` or later.
CVE-2026-35253 Open Redirect in oracle (CVE-2026-35253)
vulnerability in oracle (CVE-2026-35253). Risk of unauthorized operations or information disclosure.
CVE-2025-61669 Open Redirect in jupyter-server (CVE-2025-61669)
vulnerability in jupyter-server (CVE-2025-61669). Risk of unauthorized operations or information disclosure. Exploitable via ``google.com``. Mitigation: upgrade to `2.18.0` or later.
CVE-2026-34257 Open Redirect in sap (CVE-2026-34257)
vulnerability in sap (CVE-2026-34257). Risk of unauthorized operations or information disclosure.
CVE-2026-40037 Open Redirect in openclaw (CVE-2026-40037)
vulnerability in openclaw (CVE-2026-40037). Confidential information can be exposed externally. Mitigation: upgrade to `2026.4.8` or later.
CVE-2026-39484 Open Redirect in CVE-2026-39484 (CVE-2026-39484)
vulnerability in CVE-2026-39484 (CVE-2026-39484). Risk of unauthorized operations or information disclosure.
CVE-2026-35473 Open Redirect in wegia (CVE-2026-35473)
vulnerability in wegia (CVE-2026-35473). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
CVE-2026-35474 Open Redirect in wegia (CVE-2026-35474)
vulnerability in wegia (CVE-2026-35474). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
CVE-2026-35475 Open Redirect in wegia (CVE-2026-35475)
vulnerability in wegia (CVE-2026-35475). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
CVE-2026-35410 Vulnerability in monospace (CVE-2026-35410)
vulnerability in monospace (CVE-2026-35410). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.16.1` or later.
CVE-2026-35411 Open Redirect in monospace (CVE-2026-35411)
vulnerability in monospace (CVE-2026-35411). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.16.1` or later.
CVE-2026-35404 Open Redirect in openedx (CVE-2026-35404)
vulnerability in openedx (CVE-2026-35404). Risk of unauthorized operations or information disclosure.
CVE-2026-35472 Open Redirect in wegia (CVE-2026-35472)
vulnerability in wegia (CVE-2026-35472). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
CVE-2026-35396 Open Redirect in wegia (CVE-2026-35396)
vulnerability in wegia (CVE-2026-35396). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
CVE-2026-35398 Open Redirect in wegia (CVE-2026-35398)
vulnerability in wegia (CVE-2026-35398). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.9` or later.
CVE-2018-25245 Open Redirect in dos (CVE-2018-25245)
vulnerability in dos (CVE-2018-25245). Risk of unauthorized operations or information disclosure.
CVE-2026-33709 Open Redirect in jupyter (CVE-2026-33709)
vulnerability in jupyter (CVE-2026-33709). Risk of unauthorized operations or information disclosure.
CVE-2026-5467 Open Redirect in github.com/casdoor/casdoor (CVE-2026-5467)
vulnerability in github.com/casdoor/casdoor (CVE-2026-5467). Risk of unauthorized operations or information disclosure.
CVE-2026-34847 Open Redirect in hoppscotch (CVE-2026-34847)
vulnerability in hoppscotch (CVE-2026-34847). Risk of unauthorized operations or information disclosure.
CVE-2026-34931 Open Redirect in hoppscotch (CVE-2026-34931)
vulnerability in hoppscotch (CVE-2026-34931). Successful exploitation can lead to full system takeover.
CVE-2026-34083 Vulnerability in signalk (CVE-2026-34083)
vulnerability in signalk (CVE-2026-34083). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
CVE-2026-3872 Open Redirect in redhat (CVE-2026-3872)
vulnerability in redhat (CVE-2026-3872). Confidential information can be exposed externally.
CVE-2026-34442 Vulnerability in laravel (CVE-2026-34442)
vulnerability in laravel (CVE-2026-34442). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
CVE-2026-32113 Open Redirect in discourse (CVE-2026-32113)
vulnerability in discourse (CVE-2026-32113). Risk of unauthorized operations or information disclosure.
CVE-2026-4799 Open Redirect in search-guard (CVE-2026-4799)
vulnerability in search-guard (CVE-2026-4799). Risk of unauthorized operations or information disclosure.
CVE-2026-1166 Open Redirect in hitachi (CVE-2026-1166)
vulnerability in hitachi (CVE-2026-1166). Risk of unauthorized operations or information disclosure.
CVE-2026-20994 Open Redirect in samsung (CVE-2026-20994)
vulnerability in samsung (CVE-2026-20994). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →