In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthe
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthe
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP
Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization
PbootCMS 3.2.8 is vulnerable to URL Redirect.
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect UR
An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling o
Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vu
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vu
Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verif
EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "P
Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker t
URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manag
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages t
Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url paramet
An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redire
Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect`
An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and
Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users b
HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attac
A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of
A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerabilit
SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measu
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo
pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorre
URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issu
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAu
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Buil
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Freshworks Freshdesk (official).This issue affects
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Deepen Bajracharya Video Conferencing with Zoom.Thi
An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanit
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ILLID Share This Image.This issue affects Share Thi
A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow
A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote
OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the defau
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to c
The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulner
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal Buy Now Button.This issu
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issu
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in tomlister Payflex Payment Gateway payflex-payment-g
The web server of affected devices does not properly validate input that is used for a user redirection. This could allo
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership After Login Redirectio
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Metagauss EventPrime eventprime-event-calendar-mana
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in quomodosoft ElementsReady Addons for Elementor elem
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started