Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Omgf HIGH 8.1
CVE-2021-24639

The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which …

Fix: 4.5.4+
Fix from $1,950 2021-09-20
Timetable And Event Schedule MEDIUM 5.4
CVE-2021-24584

The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with t…

Fix: 2.4.2+
Fix from $1,600 2021-09-20
Tiny File Manager HIGH 8.8
CVE-2021-40965

A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload fil…

Fix: after 2.4.6
Fix from $1,950 2021-09-15
Metinfo HIGH 8.8
CVE-2020-21126

MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.

No fix yet
Fix from $1,950 2021-09-15
Glpi HIGH 8.8
CVE-2021-39209

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Fo…

Fix: 9.5.6+
Fix from $1,950 2021-09-15
Laiketui HIGH 8.8
CVE-2020-19159

Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action…

No fix yet
Fix from $1,950 2021-09-15
Big Ip Access Policy Manager HIGH 8.8
CVE-2021-23026

BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x an…

Fix: after 16.0.1.1
Fix from $1,950 2021-09-14
Maccms MEDIUM 6.5
CVE-2020-21081

A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted …

No fix yet
Fix from $1,600 2021-09-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2021-23050

On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on all versions before 3.5.0, whe…

Fix: 3.5.0 / 15.1.3.1+
Fix from $1,950 2021-09-14
Sinec Network Management System HIGH 8.8
CVE-2021-37201

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). The web interface of affected devices is vulnerable to a Cross-Site Reque…

Fix: 1.0+
Fix from $1,950 2021-09-14
Kitecms HIGH 8.8
CVE-2020-20671

A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account.

No fix yet
Fix from $1,950 2021-09-13
Simple E Commerce Shopping Cart HIGH 8.8
CVE-2021-24620

The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable D…

Fix: after 2.2.5
Fix from $1,950 2021-09-13
Email Artillery MEDIUM 6.8
CVE-2021-24490

The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arb…

Fix: after 4.1
Fix from $1,600 2021-09-13
Fileviewer HIGH 8.8
CVE-2021-24491

The Fileviewer WordPress plugin through 2.2 does not have CSRF checks in place when performing actions such as upload and delete files. As a result, …

Fix: after 2.2
Fix from $1,950 2021-09-13
Jeesns HIGH 8.8
CVE-2020-19280

Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.

No fix yet
Fix from $1,950 2021-09-09
Mipcms MEDIUM 6.5
CVE-2020-19264

A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/ApiAdminUser/itemAdd.

No fix yet
Fix from $1,600 2021-09-09
Dswjcms MEDIUM 5.7
CVE-2020-19268

A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator …

No fix yet
Fix from $1,600 2021-09-09
Mipcms HIGH 8.8
CVE-2020-19263

A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily escalate user privileges to administrator via index.php?s=/user/…

No fix yet
Fix from $1,950 2021-09-09
Fuel Cms MEDIUM 6.5
CVE-2021-38721

FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability

Patch available
Fix from $1,600 2021-09-09
Sqlite Web HIGH 8.8
CVE-2021-23404

This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request …

No fix yet
Fix from $1,950 2021-09-08
Cliniccases HIGH 8.8
CVE-2021-38705

ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticated user following a malicious …

No fix yet
Fix from $1,950 2021-09-07
Better Errors HIGH 8.8
CVE-2021-39197

better_errors is an open source replacement for the standard Rails error page with more information rich error pages. It is also usable outside of Ra…

Fix: 2.8.0+
Fix from $1,950 2021-09-07
Arubaos MEDIUM 6.5
CVE-2019-5318

A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6.x.x.x: all versions, 8.x.x.x…

Fix: 8.8.0.0+
Fix from $1,600 2021-09-07
Sd Wan HIGH 8.1
CVE-2021-37725

A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software versio…

Fix: 2.2.0.4 / 8.3.0.15+
Fix from $1,950 2021-09-07
Keyword Meta MEDIUM 5.4
CVE-2021-24611

The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, …

Fix: after 3.0
Fix from $1,600 2021-09-06
Wtcms MEDIUM 6.5
CVE-2020-20343

WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arb…

No fix yet
Fix from $1,600 2021-09-01
Iwebshop HIGH 8.8
CVE-2020-19047

Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/ind…

No fix yet
Fix from $1,950 2021-08-31
Saml HIGH 8.8
CVE-2021-21678

Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

Fix: after 2.0.7
Fix from $1,950 2021-08-31
Azure Ad HIGH 8.8
CVE-2021-21679

Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenki…

Fix: after 179.vf6841393099e
Fix from $1,950 2021-08-31
Rundeck MEDIUM 6.8
CVE-2021-39133

Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, a user w…

Fix: 3.3.14 / 3.4.3+
Fix from $1,600 2021-08-30