A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC vers
A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affec
A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Aff
A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.
jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user cli
An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain
A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affect
This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prio
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authe
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After success
A vulnerability classified as problematic has been found in Arno0x TwoFactorAuth. This affects an unknown part of the fi
A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Af
A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by
A vulnerability was found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this issue is some un
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console acces
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). After success
Microsoft SharePoint Server Spoofing Vulnerability
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting fr
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown fun
An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting fro
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network a
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a UR
Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vul
The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows
An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerabil
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a mani
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL
mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger
Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multipl
alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to
In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the aut
Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie cons
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui
BookWyrm is a social network for tracking your reading, talking about books, writing reviews, and discovering what to re
Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may b
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS S
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS S
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1
The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applica
A vulnerability was found in eolinker apinto-dashboard. It has been rated as problematic. This issue affects some unknow
A vulnerability was found in oils-js. It has been declared as critical. This vulnerability affects unknown code of the f
forge is vulnerable to URL Redirection to Untrusted Site
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host"
An open redirect vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerabili
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started