VulnSea

CWE-601

CVEs classified under CWE-601, newest first.

140 CVEsRSS

CVE-2026-88887High· 8.6
1w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the foll…

Twilightrenovatebot · renovateEPSS 0.30%via NVD
CVE-2026-88880High· 8.6
1w ago

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify…

Twilightrenovatebot · renovateEPSS 0.36%via NVD
CVE-2026-88882High· 8.6
1w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from …

Twilightrenovatebot · renovateEPSS 0.30%via NVD
CVE-2026-88881High· 8.6
1w ago

Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials config…

Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials config…

Twilightrenovatebot · renovateEPSS 0.30%via NVD
CVE-2026-8323Critical· 9.3
1w ago

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.

MidnightArmiya Information Technologies Ltd. Co. · Access Control SystemEPSS 0.25%via NVD
CVE-2026-86756Medium· 6.1
1w ago

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs)

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended ses…

Sunlitsnipeitapp · snipe-itEPSS 0.20%via NVD
CVE-2026-78377Medium· 6.1
1w ago

URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc

URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Phishing. …

SunlitYordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. · Library Information and Document Automation ProgramEPSS 0.18%via NVD
CVE-2026-81741Medium· 4.7
1w ago

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redir…

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allowing unauthenticated attackers to redir…

SunlitEPSS 0.17%via NVD
CVE-2026-28572High· 7.8
1w ago

In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack

In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-28631High· 7.8
1w ago

In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack

In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-28630Low· 3.3
1w ago

In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack

In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not neede…

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-28626High· 7.3
1w ago

In onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection

In onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection . This could lead to local escalation of privilege with no additional execution privileges needed. User interact…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-84389Low· 3.1
1w ago

A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

SunlitFortinet · FortiSIEMEPSS 0.14%via NVD
CVE-2026-84282Medium· 6.5
1w ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server UR…

SunlitAscensio System SIA / OnlyOffice · ONLYOFFICE ownCloud integration pluginEPSS 0.20%via NVD
CVE-2026-86351Medium· 6.1
2w ago

Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /

Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin with / but resolv…

Sunlitmisp-project · mispEPSS 0.19%via NVD
CVE-2026-86256Medium· 5.4PoC
2w ago

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py)

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET param…

Twilightwger-project · wgerEPSS 0.18%via NVD
CVE-2026-86205Medium· 5.4PoC
2w ago

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft a same-origin URL with a double-slash …

Twilighth3js · h3EPSS 0.20%via NVD
CVE-2026-81423Medium· 4.3
2w ago

The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leverage…

The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leverage…

SunlitEPSS 0.21%via NVD
CVE-2026-85676Medium· 4.3
2w ago

Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement

Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redir_url parameter to any short link to redir…

Sunlitdubinc · dubEPSS 0.24%via NVD
CVE-2026-53728High· 7.1PoC
2w ago

Medplum is a developer platform that enables development of healthcare apps

Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts attacker-controlled redirect URIs that only need to start with a r…

Midnightmedplum · medplumEPSS 0.14%via NVD
CVE-2026-49456Low· 3.1
2w ago

Waku is the minimal React framework

Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161) accepts an arbitrary string and reflects it unchange…

Sunlitwaku · wakuEPSS 0.30%via NVD
CVE-2026-53683Medium· 4.3
2w ago

Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed o…

SunlitRed Hat · ipaEPSS 0.16%via CVEORG
CVE-2026-82467Medium· 4.7
3w ago

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double s…

SunlitEPSS 0.19%via NVD
CVE-2026-82464Medium· 6.1
3w ago

pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern

pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft logout links with backslash-prefixed e…

SunlitEPSS 0.20%via NVD
CVE-2026-81342Medium· 4.7
3w ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.

SunlitEPSS 0.17%via NVD
CVE-2026-55834Medium· 4.3
3w ago

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+pag…

Sunlitpocket-id · github.com/pocket-id/pocket-id/backendEPSS 0.27%via NVD
CVE-2026-47883Medium· 6.1PoC
3w ago

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6…

Twilightvmware · spring_frameworkEPSS 0.19%via NVD
CVE-2026-47887Medium· 6.1
3w ago

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spri…

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spri…

Sunlitvmware · spring_frameworkEPSS 0.17%via NVD
CVE-2026-42350Low
3w ago

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

Sunlitakuity · github.com/akuity/kargoEPSS 0.31%via GHSA
CVE-2026-81029High· 8.1
3w ago

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any confi…

TwilightEPSS 0.30%via NVD
CWE-601 vulnerabilities (CVEs) — page 2 · VulnSea