The web application sends a redirect to another location, but instead of exiting, it executes additional code.
Volume of CVEs assigned to CWE-698 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48766HIGH NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal | May 13, 2025 | 8.6 | 82 | NO | YES |
CVE-2026-2699CRITICAL Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration a | Apr 2, 2026 | 9.8 | 81 | NO | YES |
CVE-2026-58455CRITICAL Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing ex | Jul 2, 2026 | 9.8 | 45 | NO | NO |
CVE-2025-8350CRITICAL Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTT | Feb 19, 2026 | 9.8 | 35 | NO | NO |
CVE-2025-6967HIGH Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authe | Feb 10, 2026 | 8.7 | 29 | NO | NO |
CVE-2026-3262HIGH A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interfa | Feb 26, 2026 | 8.8 | 28 | NO | NO |
CVE-2024-2572CRITICAL A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /task-details | Mar 18, 2024 | 9.8 | 28 | NO | NO |
CVE-2026-3264HIGH A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of the component Administr | Feb 26, 2026 | 8.8 | 27 | NO | NO |
CVE-2024-2570CRITICAL A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file /edit-task.php. The ma | Mar 18, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-2569CRITICAL A vulnerability was found in SourceCodester Employee Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin- | Mar 18, 2024 | 9.8 | 27 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.