Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Kagemai HIGH 8.8
CVE-2021-20687

Cross-site request forgery (CSRF) vulnerability in Kagemai 0.8.8 allows remote attackers to hijack the authentication of administrators via unspecifi…

Mitigation only
Fix from $1,950 2021-04-07
Radius Manager HIGH 8.8
CVE-2021-30147

DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.

No fix yet
Fix from $1,950 2021-04-07
Database Backups HIGH 8.1
CVE-2021-24174

The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such a…

Fix: after 1.2.2.6
Fix from $1,950 2021-04-05
Contact Form 7 HIGH 8.8
CVE-2021-24159

Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScr…

Fix: after 3.1.9
Fix from $1,950 2021-04-05
Responsive Menu HIGH 8.8
CVE-2021-24161

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip …

Fix: 4.0.4+
Fix from $1,950 2021-04-05
Responsive Menu HIGH 8.8
CVE-2021-24162

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all ne…

Fix: 4.0.4+
Fix from $1,950 2021-04-05
Ninja Forms MEDIUM 5.4
CVE-2021-24166

The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had n…

Fix: 3.4.34+
Fix from $1,600 2021-04-05
Vm Backups MEDIUM 6.1
CVE-2021-24173

The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update t…

Fix: after 1.0
Fix from $1,600 2021-04-05
Opc Toolbox HIGH 8.8
CVE-2021-29660

A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the …

Fix: after 4.10.1.13035
Fix from $1,950 2021-04-02
Gocd HIGH 8.8
CVE-2021-25924

In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoin…

Fix: 21.2.0+
Fix from $1,950 2021-04-01
Mahara MEDIUM 6.5
CVE-2021-29349

Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The application fails…

No fix yet
Fix from $1,600 2021-03-31
Build With Parameters HIGH 8.8
CVE-2021-21629

A cross-site request forgery (CSRF) vulnerability in Jenkins Build With Parameters Plugin 1.5 and earlier allows attackers to build a project with at…

Fix: after 1.5
Fix from $1,950 2021-03-30
Owasp Dependency Track HIGH 8.8
CVE-2021-21633

A cross-site request forgery (CSRF) vulnerability in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers to connect to an attack…

Fix: after 3.1.0
Fix from $1,950 2021-03-30
Team Foundation Server HIGH 8.8
CVE-2021-21638

A cross-site request forgery (CSRF) vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers to connect to an atta…

Fix: after 5.157.1
Fix from $1,950 2021-03-30
Wifi Mini Spy 1080p Hd Security Ip Camera Firmware HIGH 8.8
CVE-2020-19639

Cross Site Request Forgery (CSRF) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B, via all fields to WebUI.

Mitigation only
Fix from $1,950 2021-03-30
Omnikey 5427 Firmware HIGH 8.8
CVE-2020-36283

HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated …

Mitigation only
Fix from $1,950 2021-03-24
Libvirt Agents HIGH 8.8
CVE-2021-21627

A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to stop hypervisor domains.

Fix: after 1.9.0
Fix from $1,950 2021-03-18
Grav Cms HIGH 8.8
CVE-2020-29553

The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (…

Fix: after 1.6.31
Fix from $1,950 2021-03-15
Espressreports Es HIGH 8.8
CVE-2020-24983

An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses a POST req…

No fix yet
Fix from $1,950 2021-03-11
Espressreports Es HIGH 8.8
CVE-2020-24984

An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin lev…

No fix yet
Fix from $1,950 2021-03-11
Experience Manager MEDIUM 6.5
CVE-2020-14989

An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended.

Fix: after 14.2.2
Fix from $1,600 2021-03-11
Gs116e Firmware HIGH 8.8
CVE-2020-35223

The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omittin…

Mitigation only
Fix from $1,950 2021-03-10
Rumpus HIGH 8.8
CVE-2020-27574

Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions…

Mitigation only
Fix from $1,950 2021-03-08
Gatemanager Firmware HIGH 8.8
CVE-2020-29030

Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: S…

Fix: 9.4.621054022+
Fix from $1,950 2021-03-05
Airwave HIGH 8.8
CVE-2021-26961

A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2…

Fix: 8.2.12.0+
Fix from $1,950 2021-03-05
Airwave HIGH 8.8
CVE-2021-26960

A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2…

Fix: 8.2.12.0+
Fix from $1,950 2021-03-05
Zabbix HIGH 8.8
CVE-2021-27927

In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthent…

Fix: after 5.2.3
Fix from $1,950 2021-03-03
E107 HIGH 8.8
CVE-2021-27885

usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.

Fix: after 2.3.0
Fix from $1,950 2021-03-02
Nx Os HIGH 8.1
CVE-2021-1227

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery…

Mitigation only
Fix from $1,950 2021-02-24
Configuration Slicing HIGH 8.8
CVE-2021-21617

A cross-site request forgery (CSRF) vulnerability in Jenkins Configuration Slicing Plugin 1.51 and earlier allows attackers to apply different slice …

Fix: after 1.51
Fix from $1,950 2021-02-24