Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-601 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 188 | 183 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▃
2025-09 1 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 15 · 2026-06 58 · 2026-07 84 · 2026-08 25
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-8883 | 6.1 | 78.7 | — | Keycloak: vulnerable redirect uri validation results in open redirec |
| CVE-2026-64645 | 8.3 | 53.2 | — | Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination ho… |
| CVE-2026-47645 | 8.8 | 52.4 | — | Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability |
| CVE-2026-51564 | 4.9 | 48.6 | — | — |
| CVE-2026-40961 | 7.2 | 48.3 | — | Apache Airflow: Open Redirect Bypass Vulnerability |
| CVE-2024-43543 | 6.8 | 47.3 | — | Windows Mobile Broadband Driver Remote Code Execution Vulnerability |
| CVE-2024-43536 | 6.8 | 47.1 | — | Windows Mobile Broadband Driver Remote Code Execution Vulnerability |
| CVE-2026-41106 | 9.3 | 42.6 | — | Microsoft 365 Copilot Elevation of Privilege Vulnerability |
| CVE-2026-66829 | 2.3 | 40.8 | — | html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced c… |
| CVE-2026-67178 | 7.8 | 40.3 | — | Open Redirect in MISP Installer-Generated Apache Configuration |
| CVE-2026-52802 | 5.4 | 38.0 | — | Gogs: Open Redirect via redirect_to in Gogs |
| CVE-2026-14902 | 6.1 | 36.0 | — | — |
| CVE-2026-10839 | 5.1 | 35.2 | — | Open redirection vulnerability in Password Manager |
| CVE-2026-48895 | 2.1 | 34.3 | — | Apache APISIX: Cas-auth Host header influence on CAS service URL |
| CVE-2026-44915 | 2.1 | 33.4 | — | Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value |
| CVE-2026-33102 | 9.3 | 33.2 | — | Microsoft 365 Copilot Elevation of Privilege Vulnerability |
| CVE-2026-35259 | 8.8 | 32.3 | — | — |
| CVE-2026-53573 | 4.8 | 31.0 | — | core-geonetwork has an Open Redirect Bypass |
| CVE-2026-47070 | 6.0 | 30.5 | — | HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect… |
| CVE-2026-10562 | 5.9 | 30.5 | — | Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface |