Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
S3900 24t4s Firmware HIGH 8.8
CVE-2020-24033

An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allo…

Fix: after 1.7.0
Fix from $1,950 2020-10-22
Firepower Extensible Operating System HIGH 8.8
CVE-2020-3456

A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cros…

Patch available
Fix from $1,950 2020-10-21
Nagios Xi MEDIUM 6.5
CVE-2020-5790

Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into cli…

No fix yet
Fix from $1,600 2020-10-20
Es7510 Xt Firmware HIGH 8.8
CVE-2020-12502

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…

No fix yet
Fix from $1,950 2020-10-15
Live Chat Live Support HIGH 8.8
CVE-2020-5642

Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote attackers to hijack the authentic…

Fix: after 3.1.0
Fix from $1,950 2020-10-15
Curam Social Program Management MEDIUM 6.5
CVE-2020-4773

A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a u…

Mitigation only
Fix from $1,600 2020-10-12
D6200 Firmware HIGH 8.8
CVE-2020-26912

Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.…

Fix: 1.0.0.42 / 1.0.0.66+
Fix from $1,950 2020-10-09
Garfield Petshop HIGH 8.8
CVE-2020-26522

A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack t…

Fix: after 2020-10-01
Fix from $1,950 2020-10-09
Formalms HIGH 8.8
CVE-2020-26802

forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=saveinfo via a GET request to …

No fix yet
Fix from $1,950 2020-10-08
Maven Cascade Release MEDIUM 6.5
CVE-2020-2295

A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds …

Fix: after 1.3.2
Fix from $1,600 2020-10-08
Pyrocms HIGH 7.1
CVE-2020-25263

PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be …

No fix yet
Fix from $1,950 2020-10-08
Monocms MEDIUM 6.5
CVE-2020-25986

A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.

No fix yet
Fix from $1,600 2020-10-06
Wn530h4 Firmware HIGH 8.1
CVE-2020-12123

CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, beca…

Mitigation only
Fix from $1,950 2020-10-02
Trb245 Firmware HIGH 8.8
CVE-2020-5786EPSS 9%

Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legi…

No fix yet
Fix from $1,950 2020-10-01
Mbconnect24 MEDIUM 6.5
CVE-2020-24570

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24pr…

Fix: after 2.6.1
Fix from $1,600 2020-09-30
Lansweeper HIGH 8.0
CVE-2020-13658

In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges wit…

No fix yet
Fix from $1,950 2020-09-30
Observium MEDIUM 6.5
CVE-2020-25142

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable if any links and forms lack an unpredictable C…

Mitigation only
Fix from $1,600 2020-09-25
Multi User HIGH 8.8
CVE-2020-23837

A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) us…

No fix yet
Fix from $1,950 2020-09-25
Ismartgate Pro Firmware MEDIUM 6.5
CVE-2020-12281

iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to create a new user via /index.php.

No fix yet
Fix from $1,600 2020-09-24
Ismartgate Pro Firmware HIGH 8.8
CVE-2020-12282

iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible via /index.php. (This can be …

No fix yet
Fix from $1,950 2020-09-24
Ismartgate Pro Firmware MEDIUM 6.5
CVE-2020-12840

ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php

No fix yet
Fix from $1,600 2020-09-24
Ismartgate Pro Firmware MEDIUM 6.5
CVE-2020-12841

ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php

No fix yet
Fix from $1,600 2020-09-24
Ismartgate Pro Firmware MEDIUM 6.5
CVE-2020-12280

iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to open/close a specified garage door/gate via /isg/opendoor.php.

No fix yet
Fix from $1,600 2020-09-24
Helios Glinq MEDIUM 5.4
CVE-2020-5783

In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.

No fix yet
Fix from $1,600 2020-09-23
Warnings HIGH 8.8
CVE-2020-2280

A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execute arbitrary code.

Fix: after 5.0.1
Fix from $1,950 2020-09-23
Lockable Resources MEDIUM 5.4
CVE-2020-2281

A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock…

Fix: after 2.8
Fix from $1,600 2020-09-23
Unified Communications Manager HIGH 8.8
CVE-2020-3135

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated, remote attacker t…

Fix: 11.5+
Fix from $1,950 2020-09-23
Hosted Collaboration Mediation Fulfillment MEDIUM 6.5
CVE-2020-3124

A vulnerability in the web-based interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) could allow an unauthenticated, remote attacke…

Fix: 12.5+
Fix from $1,600 2020-09-23
iOS HIGH 8.8
CVE-2019-16009

A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request …

Fix: 16.1.1+
Fix from $1,950 2020-09-23
Ozeki Ng Sms Gateway HIGH 8.8
CVE-2020-14025

Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making…

Fix: after 4.17.6
Fix from $1,950 2020-09-22