VulnSea

CWE-601

CVEs classified under CWE-601, newest first.

160 CVEsRSS

CVE-2026-47645High· 8.8
3mo ago

Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft 365 CopilotEPSS 0.76%via CVEORG
CVE-2026-12049Medium· 4.3
3mo ago

Open redirect in pgAdmin 4's multi-factor authentication flow

Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed back inside pgAdmin, so an authenticated …

▾ Sunlitpgadmin · pgadmin_4EPSS 0.38%via NVD
CVE-2026-55660High
3mo ago

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

▾ Twilighttinacms · tinacmsEPSS 0.28%via GHSA
CVE-2026-55185Medium
3mo ago

Open Redirect Bypass in miniflux-v2

Open Redirect Bypass in miniflux-v2

▾ Sunlitv2 · miniflux.app/v2EPSS 0.59%via GHSA
CVE-2026-25779Medium
3mo ago

Gitea: Open Redirect via redirect_to

Gitea: Open Redirect via redirect_to

▾ Sunlitgo-gitea · github.com/go-gitea/giteaEPSS 0.34%via GHSA
CVE-2026-55590Medium
3mo ago

CakePHP Authentication: Open redirect weakness via backslash bypass

CakePHP Authentication: Open redirect weakness via backslash bypass

▾ Sunlitcakephp · cakephp/authenticationEPSS 0.49%via GHSA
CVE-2026-56326Medium· 6.1
3mo ago

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

▾ Sunlitnuxt · nuxtEPSS 0.36%via GHSA
CVE-2026-48784Medium
3mo ago

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization

▾ Sunlitsymfony · symfony/routingEPSS 0.35%via GHSA
CVE-2026-47347Medium
3mo ago

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.48%via GHSA
CVE-2026-48856Medium· 6.5
3mo ago

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without c…

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without c…

▾ Sunliterlang · erlang/inetsEPSS 0.56%via NVD
CVE-2026-41706Medium· 6.1
3mo ago

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versi…

▾ Sunlitvmware · spring_securityEPSS 0.30%via NVD
CVE-2026-41008Medium· 6.1
3mo ago

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unva…

▾ Sunlitbroadcom · spring_authorization_serverEPSS 0.25%via NVD
CVE-2026-47991Medium· 6.1
3mo ago

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that re…

▾ Sunlitadobe · experience_managerEPSS 0.46%via NVD
CVE-2026-41844Medium· 4.2
3mo ago

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect…

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect…

▾ Sunlitvmware · spring_frameworkEPSS 0.23%via NVD
CVE-2026-41479Medium· 5.4
3mo ago

Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type

Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type

▾ Sunlitauthlib · authlibEPSS 0.26%via GHSA
CVE-2026-2813Medium· 4.7
4mo ago

ArcGIS Server contains an input validation weakness in the login redirection workflow

ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redir…

▾ Sunlitesri · arcgis_serverEPSS 0.32%via NVD
CVE-2026-41226Medium· 4.7
5mo ago

Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor

Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become …

▾ SunlitEPSS 0.38%via NVD
CVE-2026-33102Critical· 9.3
5mo ago

Microsoft 365 Copilot Elevation of Privilege Vulnerability

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft 365 CopilotEPSS 0.72%via CVEORG
CVE-2026-40037Medium· 6.5
5mo ago

OpenClaw < 2026.3.31 - Unsafe Request Body Replay via fetchWithSsrFGuard Cross-Origin Redirects

OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering red…

▾ SunlitOpenClaw · OpenClawEPSS 0.55%via CVEORG
CVE-2018-25245High· 7.5
5mo ago

7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality

7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 7700 characters into the se…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-34442Medium· 5.4
6mo ago

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary do…

▾ Sunlitfreescout · freescoutEPSS 0.32%via NVD
CVE-2026-32113Medium· 6.1
6mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the enter action in StaticController reads the sso_destination…

▾ Sunlitdiscourse · discourseEPSS 0.34%via NVD
CVE-2026-4799Medium· 4.3
6mo ago

In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.

In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.

▾ Sunlitsearch-guard · flxEPSS 0.29%via NVD
CVE-2026-1166Medium· 4.3
6mo ago

Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8.

Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8.

▾ Sunlithitachi · ops_center_administratorEPSS 0.18%via NVD
CVE-2026-20123Medium· 4.3
7mo ago

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This…

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This…

▾ Sunlitcisco · evolved_programmable_network_managerEPSS 0.19%via NVD
CVE-2025-68616High· 7.5PoC
8mo ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal ne…

▾ Midnightkozea · weasyprintEPSS 0.71%via NVD
CVE-2025-14524Medium· 5.3
8mo ago

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target…

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target…

▾ Sunlithaxx · curlEPSS 0.66%via NVD
CVE-2025-47890Low· 2.6
11mo ago

An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7…

An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7…

▾ Sunlitfortinet · fortiproxyEPSS 0.25%via NVD
CVE-2025-10229Medium· 4.3
1y ago

A vulnerability has been found in Freshwork up to 1.2.3

A vulnerability has been found in Freshwork up to 1.2.3. This impacts an unknown function of the file /api/v2/logout. Such manipulation of the argument post_logout_redirect_uri leads to open redirect. The attack can be executed remotely.…

▾ SunlitEPSS 0.33%via NVD
CVE-2025-50181Medium· 5.3
1y ago

urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation (CVE-2025-50181)

A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.47%via CSAF
CWE-601 vulnerabilities (CVEs) — page 5 · VulnSea