Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Netcrunch MEDIUM 5.4
CVE-2019-14481

AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a log…

No fix yet
Fix from $1,600 2020-12-16
N Central HIGH 8.8
CVE-2020-25622

An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

Mitigation only
Fix from $1,950 2020-12-16
Che HIGH 7.1
CVE-2020-14368

A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE…

Fix: 7.14.0+
Fix from $1,950 2020-12-14
Xhq HIGH 8.8
CVE-2019-19289

A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsus…

Fix: 6.1.0.0+
Fix from $1,950 2020-12-14
Edgemax Edgepower 24v Firmware HIGH 8.8
CVE-2020-8282

A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able …

Fix: after 1.7.0
Fix from $1,950 2020-12-14
Digital Asset Management HIGH 8.8
CVE-2020-28858

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made b…

Fix: after 12.0.19
Fix from $1,950 2020-12-14
Tikiwiki Cms\/groupware HIGH 8.8
CVE-2020-29254

TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site req…

No fix yet
Fix from $1,950 2020-12-11
Ultimate Category Excluder HIGH 8.8
CVE-2020-35135

The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF.

Fix: 1.2+
Fix from $1,950 2020-12-11
Shelve Project HIGH 8.1
CVE-2020-2321

A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a …

Fix: after 3.0
Fix from $1,950 2020-12-03
Cloudforms MEDIUM 6.3
CVE-2020-14369

This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a…

Fix: after 5.11
Fix from $1,600 2020-12-02
Textpattern HIGH 8.8
CVE-2020-29458

Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

No fix yet
Fix from $1,950 2020-12-02
Hcl Domino MEDIUM 6.5
CVE-2020-4127

HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under anothe…

Fix: 9.0.1 / 10.0.1+
Fix from $1,600 2020-11-30
Pbootcms MEDIUM 6.5
CVE-2020-17901

Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.

No fix yet
Fix from $1,600 2020-11-30
Akka Http Session HIGH 8.8
CVE-2020-7780

This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before …

Fix: after 0.5.11
Fix from $1,950 2020-11-27
Data Engineering HIGH 8.8
CVE-2020-26936

Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.

Fix: 1.1+
Fix from $1,950 2020-11-26
Fastgate Gpon Fga2130fwb Firmware HIGH 8.8
CVE-2020-13620

Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to p…

Fix: after 2020-05-26
Fix from $1,950 2020-11-24
News Script Php Pro MEDIUM 6.5
CVE-2020-25472

SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.

Mitigation only
Fix from $1,600 2020-11-24
Gs108ev3 Firmware MEDIUM 6.5
CVE-2020-5641

Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication…

Fix: after 2.06.10
Fix from $1,600 2020-11-24
Child Theme Creator HIGH 8.8
CVE-2020-28649

The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file.

Fix: 1.5.2+
Fix from $1,950 2020-11-16
Endpoint Security HIGH 8.8
CVE-2020-7332

Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows …

Fix: 10.6.1+
Fix from $1,950 2020-11-12
Subrion Cms HIGH 8.8
CVE-2019-7357

Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.

Patch available
Fix from $1,950 2020-11-10
Iprocess Workspace Browser HIGH 8.8
CVE-2020-27146

The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated …

Fix: after 11.6.0
Fix from $1,950 2020-11-10
Interscan Messaging Security Virtual Appliance HIGH 8.8
CVE-2020-27016

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability which could…

Fix: after 9.1
Fix from $1,950 2020-11-09
Ad\/ldap Connector HIGH 8.8
CVE-2020-15259

ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or c…

Fix: 5.0.13+
Fix from $1,950 2020-11-06
Verve Connect Vh510 Firmware HIGH 8.8
CVE-2020-27692

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management portal. At…

Fix: 1.0.1.6l0516+
Fix from $1,950 2020-11-04
Neoflex Video Subscription System MEDIUM 6.5
CVE-2020-22273

Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)

Mitigation only
Fix from $1,600 2020-11-04
Bmc Firmware HIGH 8.8
CVE-2020-11485

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) vulnerability in the AMI BMC …

Fix: 3.38.30+
Fix from $1,950 2020-10-29
Winston Firmware HIGH 8.8
CVE-2020-16256

The API on Winston 1.5.4 devices is vulnerable to CSRF.

No fix yet
Fix from $1,950 2020-10-28
Oscommerce HIGH 8.8
CVE-2020-27975

osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.

Fix: 1.0.5.4+
Fix from $1,950 2020-10-28
Eyoucms HIGH 8.8
CVE-2020-18129

A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.

No fix yet
Fix from $1,950 2020-10-22