CWE-698: EAR
The web application sends a redirect to another location, but instead of exiting, it executes additional code.
19 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-48766 — NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and
- CVE-2026-2699 — EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)
- CVE-2025-8350 — Authentication Bypass with Redirect in BiEticaret Software's BiEticaret CMS
- CVE-2026-58455 — Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
- CVE-2025-9848 — ScriptAndTools Real Estate Management System userlist.php redirect
- CVE-2026-61407 — Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerabi
- CVE-2025-6967 — Authentication Bypass in Sarman Soft's CMS
- CVE-2026-3264 — go2ismail Free-CRM Administrative redirect
- CVE-2025-53077 — An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without
- CVE-2026-16323 — Authentication Bypass via Execution After Redirect in FuyaSoft's Architect Panel Web Management Panel
- CVE-2026-10271 — a4m4 Student-Management-System Admin Endpoint admin redirect
Recently published
- CVE-2026-16323 — Authentication Bypass via Execution After Redirect in FuyaSoft's Architect Panel Web Management Panel
- CVE-2026-61407 — Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerabi
- CVE-2026-58455 — Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
- CVE-2026-10271 — a4m4 Student-Management-System Admin Endpoint admin redirect
- CVE-2026-2699 — EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)
- CVE-2026-3264 — go2ismail Free-CRM Administrative redirect
- CVE-2025-8350 — Authentication Bypass with Redirect in BiEticaret Software's BiEticaret CMS
- CVE-2025-6967 — Authentication Bypass in Sarman Soft's CMS
- CVE-2025-9848 — ScriptAndTools Real Estate Management System userlist.php redirect
- CVE-2025-53077 — An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without
- CVE-2024-48766 — NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and