Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-601

MITRE ↗

CWE-601

18
CRITICAL
85
HIGH
491
MEDIUM
21
LOW
652 CVEs · Page 2/14
8.0
CVE-2026-60650

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.0
CVE-2026-79662

Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClientRedirect (internal/s

7.7
CVE-2026-43576

OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoin

7.7
CVE-2026-55431

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,

7.6
CVE-2026-60641

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

7.6
CVE-2026-60642

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

7.6
CVE-2026-61181

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr

7.5
CVE-2025-68616

WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) pro

7.5
CVE-2018-25245

7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting ex

7.5
CVE-2026-46955

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions

7.5
CVE-2026-60467

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versio

7.5
CVE-2026-60658

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

7.5
CVE-2026-10545

IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect

7.4
CVE-2026-24052

Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in it

7.4
CVE-2026-59806

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to re

7.4
CVE-2026-47026

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).

7.3
CVE-2026-0508

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert m

7.3
CVE-2026-25649

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticat

7.3
CVE-2026-3872

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass

7.3
CVE-2026-32824

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

7.3
CVE-2026-60945

Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Su

7.2
CVE-2026-40961

A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe

7.2
CVE-2026-48895

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some

7.1
CVE-2026-28512

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to befo

7.1
CVE-2026-45037

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passe

7.1
CVE-2026-31982

An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of

7.1
CVE-2026-47015

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).

7.1
CVE-2025-71403

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute

7.1
CVE-2026-79786

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI wit

7.0
CVE-2026-58230

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated att

6.9
CVE-2026-53668

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow

6.8
CVE-2025-27900

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an

6.8
CVE-2026-53523

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be

6.8
CVE-2026-47045

Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.

6.5
CVE-2025-68470

React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path

6.5
CVE-2026-0484

Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker c

6.5
CVE-2026-23817

A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker

6.5
CVE-2026-40037

OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that

6.5
CVE-2026-34315

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ve

6.5
CVE-2026-48856

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Dat

6.5
CVE-2026-61082

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff

6.5
CVE-2026-69087

The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, th

6.5
CVE-2026-53586

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing

6.4
CVE-2026-61143

Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: P

6.3
CVE-2024-58342

XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does

6.1
CVE-2026-23726

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, An Open Redirect vulnerability was identified in the

6.1
CVE-2026-23727

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the

6.1
CVE-2026-23728

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the

6.1
CVE-2026-23729

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the

6.1
CVE-2026-23730

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the

Frequently Asked Questions

What is CWE-601?

CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-601?

There are 714 CVE records associated with CWE-601 in our database. Of these, 18 are critical severity, 85 are high severity, and 491 are medium severity.

How can I protect against CWE-601 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.

Detect CWE-601 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.

Get Started