Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Business Directory Plugin Easy Listing Directories HIGH 8.8
CVE-2021-24179

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue,…

Fix: 5.11+
Fix from $1,950 2021-05-06
Business Directory Plugin Easy Listing Directories MEDIUM 6.5
CVE-2021-24249

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issu…

Fix: 5.11.2+
Fix from $1,600 2021-05-06
Chamilo Lms HIGH 8.8
CVE-2020-23127

Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.

Patch available
Fix from $1,950 2021-05-06
Themegrill Demo Importer HIGH 8.8
CVE-2020-36334

themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.

Fix: 1.6.3+
Fix from $1,950 2021-05-05
Automation Server HIGH 8.8
CVE-2021-29238

CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).

Fix: 1.16.0+
Fix from $1,950 2021-05-03
Rukovoditel HIGH 8.8
CVE-2021-30224

Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.

Patch available
Fix from $1,950 2021-04-29
Phpfusion MEDIUM 6.1
CVE-2021-28280

CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML

Patch available
Fix from $1,600 2021-04-29
Homeautomation HIGH 8.8
CVE-2020-21989

HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP req…

No fix yet
Fix from $1,950 2021-04-27
Homeautomation HIGH 8.0
CVE-2020-22000

HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a …

No fix yet
Fix from $1,950 2021-04-27
Webmin HIGH 8.8
CVE-2021-31760EPSS 8%

Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature.

No fix yet
Fix from $1,950 2021-04-25
Webmin HIGH 8.8
CVE-2021-31762EPSS 9%

Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse …

No fix yet
Fix from $1,950 2021-04-25
Next Generation Communication Platform HIGH 8.8
CVE-2021-31584

Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrati…

No fix yet
Fix from $1,950 2021-04-23
Config File Provider MEDIUM 5.4
CVE-2021-21644

A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration f…

Fix: after 3.7.0
Fix from $1,600 2021-04-21
Mdaemon HIGH 8.8
CVE-2021-27181

An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to …

Fix: 20.0.4+
Fix from $1,950 2021-04-14
Ac1200 Re018 Firmware HIGH 8.8
CVE-2021-31152

Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change pas…

No fix yet
Fix from $1,950 2021-04-14
Time Tracker HIGH 8.1
CVE-2021-29436

Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In Time Tracker before version 1.19.27.5431 a Cross site re…

Fix: 1.19.27.5431+
Fix from $1,950 2021-04-13
Trestle Auth MEDIUM 6.5
CVE-2021-29435

trestle-auth is an authentication plugin for the Trestle admin framework. A vulnerability in trestle-auth versions 0.4.0 and 0.4.1 allows an attacker…

Patch available
Fix from $1,600 2021-04-13
Zxhn H168n Firmware MEDIUM 6.5
CVE-2021-21729

Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization oper…

Mitigation only
Fix from $1,600 2021-04-13
Zxcloud Irai HIGH 8.1
CVE-2021-21731

A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whe…

Fix: 6.03.04+
Fix from $1,950 2021-04-13
Papoo HIGH 8.8
CVE-2021-29054

Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface. This affects Papoo CMS Light through 21.02 and Papo…

Fix: after 21.02
Fix from $1,950 2021-04-13
Patreon Wordpress HIGH 8.1
CVE-2021-24230

The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make …

Fix: 1.7.0+
Fix from $1,950 2021-04-12
Patreon Wordpress MEDIUM 6.5
CVE-2021-24231

The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make …

Fix: 1.7.0+
Fix from $1,600 2021-04-12
Facebook HIGH 8.8
CVE-2021-24218

The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF …

Fix: 3.0.4+
Fix from $1,950 2021-04-12
Unibox U50 Firmware HIGH 8.8
CVE-2020-21884

Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/netw…

Mitigation only
Fix from $1,950 2021-04-09
Rn510 Firmware MEDIUM 5.4
CVE-2021-25326

Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connect…

No fix yet
Fix from $1,600 2021-04-09
Rn510 Firmware MEDIUM 6.5
CVE-2021-25327

Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-…

No fix yet
Fix from $1,600 2021-04-09
Application Automation Tools MEDIUM 6.5
CVE-2021-22512

Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects versio…

Fix: after 6.7
Fix from $1,600 2021-04-08
Zzcms CRITICAL 9.8
CVE-2020-23426

zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for …

No fix yet
Fix from $2,300 2021-04-08
Enterprise Resource Planning MEDIUM 6.5
CVE-2021-30112

Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application r…

No fix yet
Fix from $1,600 2021-04-08
Enterprise Resource Planning MEDIUM 6.5
CVE-2021-30114

Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request thr…

No fix yet
Fix from $1,600 2021-04-08