Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-601

MITRE ↗

CWE-601

31
CRITICAL
165
HIGH
1,323
MEDIUM
78
LOW
1,655 CVEs · Page 25/34
6.1
CVE-2021-41826

PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.

6.1
CVE-2021-20031

A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management

6.1
CVE-2021-20806

Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitra

6.1
CVE-2021-22963

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbit

6.1
CVE-2021-22942

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow att

6.1
CVE-2021-43058

An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exp

6.1
CVE-2021-41733

Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.

6.1
CVE-2021-38000 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote

6.1
CVE-2021-3989

showdoc is vulnerable to URL Redirection to Untrusted Site

6.1
CVE-2021-4000

showdoc is vulnerable to URL Redirection to Untrusted Site

6.1
CVE-2021-43532

The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that tri

6.1
CVE-2021-3829

openwhyd is vulnerable to URL Redirection to Untrusted Site

6.1
CVE-2020-18985

An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any

6.1
CVE-2021-40852

TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to

6.1
CVE-2021-20875

Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier

5.7
CVE-2021-21337

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS

5.7
CVE-2021-29456

Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on

5.4
CVE-2021-1218

A vulnerability in the web management interface of Cisco Smart Software Manager satellite could allow an authenticated,

5.4
CVE-2021-27352

An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after

5.4
CVE-2021-23384

The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slas

5.4
CVE-2021-23387

The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the UR

5.4
CVE-2021-23393

This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possibl

5.4
CVE-2020-23182

The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redire

5.4
CVE-2021-23401

This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL val

5.4
CVE-2021-35205

NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector.

5.4
CVE-2021-3851

firefly-iii is vulnerable to URL Redirection to Untrusted Site

5.4
CVE-2021-1500

A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote a

5.4
CVE-2021-36332

Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privil

5.4
CVE-2021-42564

An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (wit

5.3
CVE-2021-3664

url-parse is vulnerable to URL Redirection to Untrusted Site

4.9
CVE-2021-22526

Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

4.8
CVE-2021-21377

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports

4.8
CVE-2021-39112

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL v

4.8
CVE-2021-34763

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2021-34764

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.7
CVE-2021-1310

A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote att

4.7
CVE-2021-21291

OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google

4.7
CVE-2021-21338

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25

4.7
CVE-2021-1397

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could all

4.7
CVE-2021-1358

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t

4.7
CVE-2021-1525

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker

4.7
CVE-2021-32721

PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to

4.7
CVE-2021-32786

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co

4.7
CVE-2021-38343

The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npB

4.7
CVE-2021-39191

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co

4.7
CVE-2021-34772

A vulnerability in the web-based management interface of Cisco Orbital could allow an unauthenticated, remote attacker t

4.6
CVE-2020-29537

Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potential

4.4
CVE-2021-25655

A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any un

4.3
CVE-2021-43064

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and b

4.1
CVE-2021-36191

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below all

Frequently Asked Questions

What is CWE-601?

CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-601?

There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.

How can I protect against CWE-601 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.

Detect CWE-601 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.

Get Started