CWE-601 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-601 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2021-38000Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638…4.9%보통6.1● 실제 악용이 확인됨CVE-2012-0518Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion…4.7%보통4.7CVE-2026-77386Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthen…0.6%보통6.5CVE-2026-81913Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. A…0.5%보통5.3CVE-2026-54618Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize…0.5%심각9.4CVE-2026-92216A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function …0.4%보통5.3CVE-2026-94216A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution …0.5%낮음2.1CVE-2026-94214A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to…0.5%낮음2.1
전체 목록
66건
CVE-2026-94102A flaw has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=membe…0.4%낮음2.1
CVE-2026-101907Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter …0.4%높음7.0
CVE-2023-24034An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to …0.4%낮음3.1
CVE-2026-7527The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in a…0.4%보통4.7
CVE-2026-88880Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, al…0.4%심각9.2
CVE-2026-101090Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional…0.4%심각9.3
CVE-2026-93869Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates r…0.4%보통5.3
CVE-2026-86351Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path b…0.3%보통5.1
CVE-2026-92141Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allow…0.3%보통4.3
CVE-2026-96892A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the compo…0.3%낮음2.1
CVE-2026-95813e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorCompon…0.3%보통5.3
CVE-2026-88882Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images an…0.3%심각9.2
CVE-2026-88881Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` …0.3%심각9.2
CVE-2026-88887Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate fol…0.3%심각9.2
CVE-2026-55252OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or …0.3%보통5.1
CVE-2026-49456Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported fr…0.3%낮음3.1
CVE-2026-73191URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is c…0.3%보통6.1
CVE-2026-89307The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker t…0.3%보통5.1
CVE-2026-13277IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect a…0.3%보통4.7
CVE-2026-12985Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic…0.3%보통6.8
CVE-2026-65388A remote attacker who controls a container registry may be able to direct a client's token request to a host o…0.3%높음7.5
CVE-2026-54072Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, t…0.3%심각9.3
CVE-2026-54724Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted …0.3%보통6.1
CVE-2026-93871Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing au…0.3%보통5.1
CVE-2026-86823The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after…0.3%보통5.3
CVE-2026-8323URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. …0.3%심각9.3
CVE-2026-105128LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect us…0.3%보통5.3
CVE-2026-53989Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows una…0.3%보통5.3
CVE-2026-54915Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenti…0.3%보통5.4
CVE-2026-97325A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vuln…0.3%낮음2.1
CVE-2026-85676Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short l…0.2%보통5.3
CVE-2026-96773A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects the function…0.3%낮음2.1
CVE-2026-77609Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within t…0.2%보통6.1
CVE-2026-97165Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “r…0.2%보통5.3
CVE-2026-90453A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same requ…0.2%보통5.1
CVE-2026-15412IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a rem…0.2%보통6.5
CVE-2026-81423The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it…0.2%보통4.3
CVE-2026-86205h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails…0.2%보통5.3
CVE-2026-86756Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (…0.2%보통5.3
CVE-2026-102090Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was …0.2%보통4.3
CVE-2026-78377URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting,…0.2%보통6.1
CVE-2026-91772Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to …0.2%보통5.3
CVE-2026-83589A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter…0.2%보통6.1
CVE-2026-86256wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view…0.2%보통5.1
CVE-2026-100523Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect …0.2%보통5.1
CVE-2026-80072The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-l…0.2%보통4.7
CVE-2026-81741The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict th…0.2%보통4.7
CVE-2026-88791The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination wh…0.2%낮음3.4
CVE-2026-76720A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.0.2%보통4.3
CVE-2026-39600URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-…0.2%보통4.7
CVE-2026-53728Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the exter…0.1%높음7.1
CVE-2026-84389A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1,…0.1%낮음3.1
CVE-2026-103048URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - Coll…0.1%미평가
CVE-2026-97318The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveawa…0.1%보통6.1
CVE-2026-73599Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to…0.1%보통5.4
CVE-2026-18505IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHe…0.1%보통5.4
CVE-2026-80444URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co. AVESİS allows In…0.1%보통5.4
CVE-2019-6741This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Ga…심각9.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.