PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management
Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitra
A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbit
A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow att
An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exp
Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote
showdoc is vulnerable to URL Redirection to Untrusted Site
showdoc is vulnerable to URL Redirection to Untrusted Site
The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that tri
openwhyd is vulnerable to URL Redirection to Untrusted Site
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS
Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on
A vulnerability in the web management interface of Cisco Smart Software Manager satellite could allow an authenticated,
An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after
The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slas
The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the UR
This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possibl
The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redire
This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL val
NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector.
firefly-iii is vulnerable to URL Redirection to Untrusted Site
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote a
Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privil
An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (wit
url-parse is vulnerable to URL Redirection to Untrusted Site
Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL v
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could
A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote att
OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could all
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker
PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npB
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co
A vulnerability in the web-based management interface of Cisco Orbital could allow an unauthenticated, remote attacker t
Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potential
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any un
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and b
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below all
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started