Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-698

Execution After Redirect (EAR)

The web application sends a redirect to another location, but instead of exiting, it executes additional code.

17
Assigned CVEs
356th
Commonality Rank
8.9
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-698 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2024
2 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-48766HIGH
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal
May 13, 20258.682NOYES
CVE-2026-2699CRITICAL
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration a
Apr 2, 20269.881NOYES
CVE-2026-58455CRITICAL
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing ex
Jul 2, 20269.845NONO
CVE-2025-8350CRITICAL
Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTT
Feb 19, 20269.835NONO
CVE-2025-6967HIGH
Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authe
Feb 10, 20268.729NONO
CVE-2026-3262HIGH
A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interfa
Feb 26, 20268.828NONO
CVE-2024-2572CRITICAL
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /task-details
Mar 18, 20249.828NONO
CVE-2026-3264HIGH
A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of the component Administr
Feb 26, 20268.827NONO
CVE-2024-2570CRITICAL
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file /edit-task.php. The ma
Mar 18, 20249.827NONO
CVE-2024-2569CRITICAL
A vulnerability was found in SourceCodester Employee Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin-
Mar 18, 20249.827NONO
View all 17 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
12%
16%
6.0-6.9
12%
26%
7.0-7.9
24%
11%
8.0-8.9
53%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.9% of CVEs· 97th percentile
Nuclei
2 CVEs
11.8% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products