The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Volume of CVEs assigned to CWE-601 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,592 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-4123MEDIUM A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website tha | May 22, 2025 | 6.1 | 89 | NO | YES |
CVE-2017-1000117HIGH A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine | Oct 5, 2017 | 8.8 | 85 | NO | YES |
CVE-2018-11784MEDIUM When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the | Oct 4, 2018 | 4.3 | 83 | NO | YES |
CVE-2019-10098MEDIUM In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to a | Sep 25, 2019 | 6.1 | 79 | NO | YES |
CVE-2021-22881MEDIUM The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain " | Feb 11, 2021 | 6.1 | 78 | NO | YES |
CVE-2021-22873MEDIUM Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had pr | Jan 26, 2021 | 6.1 | 66 | NO | YES |
CVE-2023-32068MEDIUM XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible to exploit well known parameters | May 15, 2023 | 6.1 | 61 | NO | YES |
CVE-2021-38000MEDIUM Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a cr | Nov 23, 2021 | 6.1 | 60 | YES | NO |
CVE-2020-8143MEDIUM An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a s | Apr 3, 2020 | 6.1 | 59 | NO | NO |
CVE-2022-45402MEDIUM In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint. | Nov 15, 2022 | 6.1 | 58 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.