VulnSea

CWE-601

CVEs classified under CWE-601, newest first.

160 CVEsRSS

CVE-2025-50182Medium· 5.3
1y ago

urllib3: urllib3 does not control redirects in browsers and Node.js (CVE-2025-50182)

A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can en…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.39%via CSAF
CVE-2025-3155High· 7.4
1y ago

A flaw was found in Yelp

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

▾ Twilightgnome · yelpEPSS 14%via NVD
CVE-2024-8883Medium· 6.1PoC
2y ago

A misconfiguration flaw was found in Keycloak

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as author…

▾ Twilightredhat · build_of_keycloakEPSS 2.1%via NVD
CVE-2024-0953Medium· 6.1
2y ago

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerabil…

▾ Sunlitmozilla · firefox_mobileEPSS 0.30%via NVD
CVE-2023-6291High· 7.1
2y ago

A flaw was found in the redirect_uri validation logic in Keycloak

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to …

▾ Twilightredhat · keycloakEPSS 0.95%via NVD
CVE-2023-6927Medium· 4.6
2y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to…

▾ Sunlitredhat · keycloakEPSS 1.1%via NVD
CVE-2023-49061Medium· 6.1
2y ago

An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information

An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.

▾ Sunlitmozilla · firefox_mobileEPSS 0.31%via NVD
CVE-2023-29540Medium· 6.1
3y ago

Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>

Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox fo…

▾ Sunlitmozilla · firefoxEPSS 0.32%via NVD
CVE-2022-27461Medium· 6.1
4y ago

In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.

In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.

▾ Sunlitnopcommerce · nopcommerceEPSS 0.71%via NVD
CVE-2020-1059Medium· 4.3
6y ago

A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content

A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially …

▾ Sunlitmicrosoft · edgeEPSS 2.1%via NVD
CWE-601 vulnerabilities (CVEs) — page 6 · VulnSea