Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing
Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the origin
Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method
Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerabil
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bunkerity Bunker Web on Linux allows Phishing.This
OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the Uni
Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host
Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious UR
Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap
Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allo
Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may all
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerabil
Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerabil
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst pa
A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via us
A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via u
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 pr
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perf
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perf
An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPER
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This
Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper h
A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect use
The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. Thi
ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. T
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly
Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafte
VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim
A flaw was found in Keycloak's redirect_uri validation logic. This issue may allow a bypass of otherwise explicitly allo
Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session to
The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and inc
The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect
IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct ph
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing
Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum `/logout` route includes a redire
IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper valid
An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a
An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to sc
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data d
Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within th
An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, a
An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, a
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started