Total
1172 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-23184 | 1 Octopus | 2 Octopus Deploy, Octopus Server | 2024-11-21 | 6.1 Medium |
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects. | ||||
CVE-2022-23102 | 1 Siemens | 1 Sinema Remote Connect Server | 2024-11-21 | 6.1 Medium |
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks. | ||||
CVE-2022-23078 | 1 Habitica | 1 Habitica | 2024-11-21 | N/A |
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page. | ||||
CVE-2022-22919 | 1 Adenza | 1 Axiomsl Controllerview | 2024-11-21 | 6.1 Medium |
Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs. | ||||
CVE-2022-22797 | 1 Sysaid | 1 Sysaid | 2024-11-21 | 4.6 Medium |
Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" request from the url location: /CommunitySSORedirect.jsp?redirectURL=https://google.com. Unvalidated redirects and forwards are possible when a web application accepts untrusted input that could cause the web application to redirect the request to a URL contained within untrusted input. By modifying untrusted URL input to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. | ||||
CVE-2022-20794 | 1 Cisco | 2 Roomos, Telepresence Collaboration Endpoint | 2024-11-21 | 6.5 Medium |
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilities, see the Details section of this advisory. | ||||
CVE-2022-20764 | 1 Cisco | 2 Roomos, Telepresence Collaboration Endpoint | 2024-11-21 | 6.5 Medium |
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilities, see the Details section of this advisory. | ||||
CVE-2022-1774 | 1 Diagrams | 1 Drawio | 2024-11-21 | 6.1 Medium |
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7. | ||||
CVE-2022-1702 | 1 Sonicwall | 10 Sma 6200, Sma 6200 Firmware, Sma 6210 and 7 more | 2024-11-21 | 6.1 Medium |
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability. | ||||
CVE-2022-1254 | 1 Mcafee | 1 Web Gateway | 2024-11-21 | 6.1 Medium |
A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a user to a malicious website controlled by the attacker. This is possible because SWG incorrectly creates a HTTP redirect response when a user clicks a carefully constructed URL. Following the redirect response, the new request is still filtered by the SWG policy. | ||||
CVE-2022-1233 | 1 Uri.js Project | 1 Uri.js | 2024-11-21 | 6.1 Medium |
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11. | ||||
CVE-2022-1058 | 1 Gitea | 1 Gitea | 2024-11-21 | 6.1 Medium |
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. | ||||
CVE-2022-0869 | 1 Spirit-project | 1 Spirit | 2024-11-21 | 6.1 Medium |
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3. | ||||
CVE-2022-0868 | 1 Uri.js Project | 1 Uri.js | 2024-11-21 | 6.1 Medium |
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10. | ||||
CVE-2022-0697 | 1 Archivy Project | 1 Archivy | 2024-11-21 | 6.1 Medium |
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0. | ||||
CVE-2022-0692 | 1 Alltube Project | 1 Alltube | 2024-11-21 | 6.1 Medium |
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1. | ||||
CVE-2022-0645 | 1 Posthog | 1 Posthog | 2024-11-21 | 6.1 Medium |
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1. | ||||
CVE-2022-0597 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
Open Redirect in Packagist microweber/microweber prior to 1.2.11. | ||||
CVE-2022-0560 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
Open Redirect in Packagist microweber/microweber prior to 1.2.11. | ||||
CVE-2022-0283 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.7 Medium |
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL. |