An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.
Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthe
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthe
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthe
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter o
CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the c
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open R
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open
Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through t
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions
Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versi
An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause t
By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 20
Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use
Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts
A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout p
Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL
SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the
Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password re
Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and
Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to u
Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs
KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the
AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri paramet
AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedire
An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malici
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forc
Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. Thi
Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in
An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows atta
A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.
A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitra
Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs t
WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to c
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food
Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affecte
The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validat
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all r
urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does no
An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal funct
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improp
An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url
TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse e
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started