CWE-601
Low likelihoodURL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
1,628 vulnerabilities with CWE-601
CVE-2026-47015
HIGH
Oracle Corporation PeopleSoft Enterprise PeopleTools - Denial of Service
CVSS 7.1
CVE-2026-47002
MEDIUM
Oracle Enterprise Manager Base Platform 13.5, 24.1 - Unauthenticated Cross-Site Request Forgery via UI Framework
CVSS 6.1
CVE-2026-46998
HIGH
Oracle Enterprise Manager Base Platform 13.5, 24.1 - Unauthenticated Remote Code Execution via Metadata Plugin
CVSS 8.8
CVE-2026-8284
MEDIUM
Open Redirect in Universal Sotware's FlexCity
CVSS 6.1
CVE-2026-16336
MEDIUM
trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect
CVSS 4.3
CVE-2026-63768
MEDIUM
cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State
CVSS 4.3
CVE-2026-61901
MEDIUM
Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2
CVSS 6.1
CVE-2026-32824
HIGH
dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Controlled Redirect Targets
CVSS 7.3
CVE-2026-7364
LOW
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
CVSS 3.1
CVE-2026-15093
MEDIUM
IBM Engineering AI Hub 1.0.0-1.2.0 - Open Redirect
CVSS 4.3
CVE-2026-63094
HIGH
SigNoz 0.133.0 SSO OAuth State Manipulation Session Token Theft
CVSS 8.1
CVE-2026-12379
MEDIUM
Qt Axivion Dashboard OAuth/OIDC - Open Redirect
CVE-2026-33213
MEDIUM
Redash 5.0.2-26.3.0 Login Redirect - Open Redirect
CVSS 6.1
CVE-2026-61451
CRITICAL
Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url
CVSS 9.6
CVE-2026-48784
MEDIUM
Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
CVSS 6.1
CVE-2026-48000
MEDIUM
Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)
CVSS 4.3
CVE-2026-45065
MEDIUM
Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
CVSS 6.1
CVE-2026-14902
MEDIUM
Ivanti Xtraction - URL Redirection to Untrusted Site ('Open Redirect')
CVSS 4.0
CVE-2026-44745
HIGH
SAP Approuter < 21.2.0 - Open Redirect in OAuth2 Login Flow
CVSS 8.1
CVE-2026-55806
MEDIUM
Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
CVSS 5.9
CVE-2026-55461
MEDIUM
Snipe-IT: Open Redirect After User Edit
CVSS 6.1
CVE-2026-59180
LOW
Apprise forwards configured auth headers across cross-origin HTTP redirects
CVSS 3.1
CVE-2026-55590
MEDIUM
CakePHP: Open redirect weakness via backslash bypass
CVSS 6.1
CVE-2026-31982
HIGH
Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0
CVSS 7.1
CVE-2026-59806
HIGH
Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpoint
CVSS 7.4
Details
Vulnerabilities
1,628
Exploit Likelihood
Low