CWE-601
Low likelihoodURL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
1,628 vulnerabilities with CWE-601
CVE-2026-60945
HIGH
Oracle Learning Management 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 7.3
CVE-2026-60911
MEDIUM
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60842
MEDIUM
Oracle Knowledge Mgmt 12.2.5-12.2.15: Unauth CSRF & Data Disclosure via HTTP Search
CVSS 6.1
CVE-2026-60685
MEDIUM
Oracle iSupport 12.2.3-12.2.15 - Unauthenticated Cross-Site Request Forgery via HTTP with Impact to Additional Products
CVSS 6.1
CVE-2026-60664
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60658
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 7.5
CVE-2026-60650
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60648
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60646
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60642
HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.6
CVE-2026-60641
HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.6
CVE-2026-60640
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.3
CVE-2026-60639
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60638
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60637
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60636
HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60635
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60634
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60633
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60632
CRITICAL
Oracle WebCenter Content 12.2.1.4.0/14.1.2.0.0: Unauth HTTP Arbitrary Data Creation, Modification, Access
CVSS 9.3
CVE-2026-60467
HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0/14.1.2.0.0 - Unauth RCE via HTTP w/ User Interaction
CVSS 7.5
CVE-2026-47051
MEDIUM
PeopleSoft PeopleTools 8.61-8.62: Authenticated CSRF with Scope Change via HTTP Request
CVSS 5.4
CVE-2026-47048
MEDIUM
PeopleSoft PeopleTools 8.61/8.62 CSRF with Data Modification & Info Disclosure via HTTP
CVSS 5.4
CVE-2026-47045
MEDIUM
Oracle DB 19.3-19.31/21.3-21.22/23.4-23.26.2 Auth RCE via JDBC Oracle Net
CVSS 6.8
CVE-2026-47026
HIGH
PeopleSoft Enterprise PeopleTools 8.61 and 8.62 - Unauthenticated Unauthorized Data Access via OpenSearch Dashboards
CVSS 7.4
Details
Vulnerabilities
1,628
Exploit Likelihood
Low