URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allo
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-phot
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in aviplugins.com Login Widget With Shortcode login-si
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.
Inadequate parsing of URLs could result into an open redirect.
Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via app
The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to,
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prio
Open Redirect in Harbor <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.
There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbu
A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown
An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified U
A vulnerability, which was classified as problematic, was found in LinuxOSsk Shakal-NG up to 1.3.3. Affected is an unkno
A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic
A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unk
Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker co
A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Foliovision FV Flowplayer Video Player.This issue a
HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to m
SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious pag
A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects a
Peering Manager is a BGP session management tool. In Peering Manager <=1.8.2, it is possible to redirect users to an arb
InstantCMS is a free and open source content management system. An open redirect was found in the ICMS2 application vers
October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrator
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerab
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Acad
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affec
user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that w
Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a l
An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability al
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP s
The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in OpenText™ Network Node Manager i (NNMi) allows URL
A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when vis
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in
StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601)
VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a
An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able
An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this param
Potential open redirect vulnerability in opentext Service Management Automation X (SMAX) versions 2020.05, 2020.08, 202
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of infor
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path
The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect servi
The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerability by a malicious
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management int
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started