Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClientRedirect (internal/s
OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoin
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr
WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) pro
7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting ex
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versio
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect
Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in it
Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to re
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).
The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert m
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticat
A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Su
A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to befo
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passe
An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute
Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI wit
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated att
React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.
React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker c
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker
OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ve
Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Dat
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff
The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, th
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: P
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, An Open Redirect vulnerability was identified in the
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 714 CVE records associated with CWE-601 in our database. Of these, 18 are critical severity, 85 are high severity, and 491 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started