Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Data Risk Manager HIGH 8.1
CVE-2020-4617

IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac…

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Soy Cms CRITICAL 9.6
CVE-2020-15182

The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects vers…

Fix: 2.0.0.4 / 3.0.2.328+
Fix from $2,300 2020-09-17
Freebox Revolution Firmware HIGH 8.8
CVE-2020-24373

A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.

Fix: 4.2.3+
Fix from $1,950 2020-09-16
Secflow 1v Firmware HIGH 8.8
CVE-2020-13259

A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to…

No fix yet
Fix from $1,950 2020-09-16
Platinum 4410 Firmware MEDIUM 6.5
CVE-2020-25015

A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices wa…

No fix yet
Fix from $1,600 2020-09-16
MongoDB HIGH 8.8
CVE-2020-2268

A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any a…

Fix: after 1.3
Fix from $1,950 2020-09-16
Blackcat Cms HIGH 8.8
CVE-2020-25453EPSS 6%

An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.

Fix: 1.4+
Fix from $1,950 2020-09-15
Spiceworks HIGH 8.8
CVE-2020-23451

Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.

Fix: after 7.5.00107
Fix from $1,950 2020-09-15
Vtenext HIGH 8.8
CVE-2020-10229

A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding use…

No fix yet
Fix from $1,950 2020-09-14
Mail Server HIGH 8.8
CVE-2020-23824

ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Admi…

No fix yet
Fix from $1,950 2020-09-11
Helpdesk MEDIUM 6.5
CVE-2018-19948

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could…

Fix: 3.0.3+
Fix from $1,600 2020-09-11
Onbase HIGH 8.8
CVE-2020-25252

An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1…

Fix: after 20.3.10.1000
Fix from $1,950 2020-09-11
Icms MEDIUM 6.5
CVE-2020-24739

A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request nor…

No fix yet
Fix from $1,600 2020-09-10
Polarion Subversion Webclient HIGH 8.1
CVE-2020-15789

A vulnerability has been identified in Polarion Subversion Webclient (All versions). The web interface could allow a Cross-Site Request Forgery (CSRF…

Mitigation only
Fix from $1,950 2020-09-09
Stock Management System HIGH 7.1
CVE-2020-23830

A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to den…

No fix yet
Fix from $1,950 2020-09-02
N Tron 702 W Firmware HIGH 8.8
CVE-2020-16208

The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by lurin…

No fix yet
Fix from $1,950 2020-09-01
Usvn HIGH 8.8
CVE-2020-25070

USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.

Fix: 1.0.10+
Fix from $1,950 2020-09-01
Magmi HIGH 8.8
CVE-2020-5776EPSS 15%

Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF…

Mitigation only
Fix from $1,950 2020-09-01
Warehouse Inventory System HIGH 8.8
CVE-2020-23836

A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remo…

Fix: after 2020-08-10
Fix from $1,950 2020-09-01
Database HIGH 8.8
CVE-2020-2240

A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts.

Fix: after 1.6
Fix from $1,950 2020-09-01
Database HIGH 8.8
CVE-2020-2241

A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified dat…

Fix: after 1.6
Fix from $1,950 2020-09-01
Blog Comments HIGH 8.1
CVE-2020-15156

In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their…

Fix: 0.7.0+
Fix from $1,950 2020-08-26
Big Ip Access Policy Manager HIGH 8.8
CVE-2020-5922

In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Si…

Fix: 12.1.5.2 / 13.1.3.4+
Fix from $1,950 2020-08-26
Codiad HIGH 8.8
CVE-2020-14043

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to down…

No fix yet
Fix from $1,950 2020-08-24
Dbhcms HIGH 8.1
CVE-2020-19886

DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.

No fix yet
Fix from $1,950 2020-08-24
Dbhcms HIGH 8.8
CVE-2020-19889

DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.

No fix yet
Fix from $1,950 2020-08-24
Openmage Long Term Support HIGH 8.0
CVE-2020-15151

OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attac…

Fix: 19.4.6 / 20.0.2+
Fix from $1,950 2020-08-20
Play Framework MEDIUM 6.5
CVE-2020-12480

In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that…

Fix: after 2.8.1
Fix from $1,600 2020-08-17
Quiz And Survey Master MEDIUM 6.5
CVE-2016-11085

php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_…

Fix: 4.7.9+
Fix from $1,600 2020-08-16
Data Loss Prevention HIGH 7.6
CVE-2020-7304

Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to e…

Fix: 11.3.28 / 11.4.200+
Fix from $1,950 2020-08-13