Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Smartstorenet HIGH 8.8
CVE-2020-27997

An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g.…

Fix: 4.1.0+
Fix from $1,950 2021-02-19
Myfaces HIGH 7.5
CVE-2021-26296

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptograph…

Fix: after 2.3.7
Fix from $1,950 2021-02-19
Open Ondemand HIGH 8.8
CVE-2020-36247

Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.

Fix: 1.5.7 / 1.6.22+
Fix from $1,950 2021-02-19
M\!dge Firmware HIGH 8.8
CVE-2021-20073

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries.

Mitigation only
Fix from $1,950 2021-02-16
Wrc 300febk A Firmware MEDIUM 6.5
CVE-2021-20646

Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentication of administrators and ex…

Mitigation only
Fix from $1,600 2021-02-12
Wrc 300febk S Firmware MEDIUM 6.5
CVE-2021-20647

Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentication of administrators and ex…

Mitigation only
Fix from $1,600 2021-02-12
Ncc Ewf100rmwh2 Firmware MEDIUM 6.5
CVE-2021-20650

Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authentication of administrators and …

Mitigation only
Fix from $1,600 2021-02-12
Lan W300n\/pr5b Firmware MEDIUM 6.5
CVE-2021-20636

Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via …

Mitigation only
Fix from $1,600 2021-02-12
Lan W300n\/rs Firmware MEDIUM 6.5
CVE-2021-20641

Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a …

Mitigation only
Fix from $1,600 2021-02-12
Cloud Access Connector MEDIUM 6.5
CVE-2020-13186

An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacke…

Fix: after 31
Fix from $1,600 2021-02-11
Security Verify Information Queue HIGH 8.8
CVE-2021-20403

IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Mitigation only
Fix from $1,950 2021-02-11
Nextgen Gallery MEDIUM 6.5
CVE-2020-35943

A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF…

Fix: 3.5.0+
Fix from $1,600 2021-02-09
Nextgen Gallery HIGH 8.8
CVE-2020-35942

A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via se…

Fix: 3.5.0+
Fix from $1,950 2021-02-09
Securetrack HIGH 8.8
CVE-2020-13460

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.

Mitigation only
Fix from $1,950 2021-02-09
Application Performance Management MEDIUM 6.5
CVE-2021-22500

Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulne…

Mitigation only
Fix from $1,600 2021-02-06
Name Directory HIGH 8.8
CVE-2021-20652

Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administ…

Fix: after 1.17.4
Fix from $1,950 2021-02-05
Squaredup MEDIUM 6.5
CVE-2020-9388

CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary cod…

Fix: 4.6+
Fix from $1,600 2021-02-03
Youtrack HIGH 8.8
CVE-2021-25765

In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.

Fix: 2020.4.4701+
Fix from $1,950 2021-02-03
Easycms HIGH 8.8
CVE-2020-24271

A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callba…

No fix yet
Fix from $1,950 2021-02-01
Star HIGH 8.8
CVE-2020-28403

A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privi…

Mitigation only
Fix from $1,950 2021-01-29
Mediawiki HIGH 8.8
CVE-2020-29004

The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.

Fix: after 1.35
Fix from $1,950 2021-01-29
Openemr HIGH 8.8
CVE-2020-13569

A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f…

No fix yet
Fix from $1,950 2021-01-28
Wg2600hp Firmware HIGH 8.8
CVE-2021-20621

Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier al…

Fix: after 1.0.2
Fix from $1,950 2021-01-28
Cakephp HIGH 8.8
CVE-2020-35239

A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CS…

Fix: after 4.1.3
Fix from $1,950 2021-01-26
Io Link Master 4 Eip Firmware HIGH 8.8
CVE-2020-12511

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.

Fix: after 1.5.48
Fix from $1,950 2021-01-22
Catalyst Center HIGH 8.8
CVE-2021-1257

A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross…

Fix: 2.1.1.0 / 5.7.6+
Fix from $1,950 2021-01-20
Akka Http Session HIGH 8.8
CVE-2020-28452

This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package com.softwaremill.akka-http-ses…

Fix: 0.6.1+
Fix from $1,950 2021-01-20
Vert.x Web HIGH 8.8
CVE-2020-35217

Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSR…

Patch available
Fix from $1,950 2021-01-20
Anchor Cms HIGH 8.8
CVE-2020-23342EPSS 12%

A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.

No fix yet
Fix from $1,950 2021-01-19
Pixelimity MEDIUM 6.8
CVE-2020-23522

Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.

No fix yet
Fix from $1,600 2021-01-19