Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Pipeline Maven Integration MEDIUM 6.5
CVE-2020-2235

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an at…

Fix: after 3.8.2
Fix from $1,600 2020-08-12
Aura Communication Manager HIGH 8.8
CVE-2020-7029

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager…

Fix: 7.1 / 8.1.0.0+
Fix from $1,950 2020-08-11
Itop HIGH 8.8
CVE-2020-12781

Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

Fix: 2.7.1+
Fix from $1,950 2020-08-10
Pghero HIGH 8.1
CVE-2020-16253

The PgHero gem through 2.6.0 for Ruby allows CSRF.

Fix: after 2.6.0
Fix from $1,950 2020-08-05
Save Server HIGH 7.6
CVE-2020-15135

save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced i…

Fix: 1.0.5+
Fix from $1,950 2020-08-04
Calendar01 HIGH 8.8
CVE-2020-5615

Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers …

Mitigation only
Fix from $1,950 2020-08-04
Trb245 Firmware HIGH 8.8
CVE-2020-5770

Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking leg…

No fix yet
Fix from $1,950 2020-08-03
Amq Online MEDIUM 5.9
CVE-2020-14319

It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks ar…

Fix: 0.32.2 / 1.5.2+
Fix from $1,600 2020-08-03
Gambio Gx HIGH 8.8
CVE-2020-10984

Gambio GX before 4.0.1.0 allows admin/admin.php CSRF.

Fix: 4.0.1.0+
Fix from $1,950 2020-07-28
Social Sharing HIGH 8.8
CVE-2020-5611

Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authenticatio…

Fix: 1.2.10+
Fix from $1,950 2020-07-27
Munkireport HIGH 8.1
CVE-2020-15882

A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines from the MunkiReport database.

Fix: 5.6.3+
Fix from $1,950 2020-07-23
Email Subscribers \& Newsletters MEDIUM 6.5
CVE-2020-5767

Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by t…

No fix yet
Fix from $1,600 2020-07-17
Librehealth Ehr HIGH 8.8
CVE-2020-11438

LibreHealth EMR v2.0.0 is affected by systemic CSRF.

No fix yet
Fix from $1,950 2020-07-15
Joomla\! MEDIUM 6.3
CVE-2020-15695

An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.

Fix: after 3.9.19
Fix from $1,600 2020-07-15
Joomla\! MEDIUM 6.3
CVE-2020-15700

An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.

Fix: after 3.9.19
Fix from $1,600 2020-07-15
Impact 360 HIGH 8.8
CVE-2019-12784

An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunctio…

No fix yet
Fix from $1,950 2020-07-14
Disclosure Management HIGH 8.8
CVE-2020-6289

SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to brow…

Mitigation only
Fix from $1,950 2020-07-14
Misp HIGH 8.8
CVE-2020-15711

In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.

Fix: 2.4.129+
Fix from $1,950 2020-07-14
Ac15 Firmware MEDIUM 6.5
CVE-2020-10986

A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause de…

No fix yet
Fix from $1,600 2020-07-13
Cmsuno MEDIUM 6.5
CVE-2020-15600

An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.

Fix: 1.6.1+
Fix from $1,600 2020-07-07
Mm Forum MEDIUM 5.4
CVE-2020-15516

The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.

Fix: after 1.9.5
Fix from $1,600 2020-07-07
Big Ip Access Policy Manager HIGH 8.8
CVE-2020-5904

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traff…

Fix: after 15.1.0.3
Fix from $1,950 2020-07-01
Nginx Controller HIGH 8.8
CVE-2020-5900

In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user in…

Fix: after 3.4.0
Fix from $1,950 2020-07-01
Wrb303n Firmware MEDIUM 6.5
CVE-2020-15043

iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresse…

No fix yet
Fix from $1,600 2020-06-29
X10drh It Bios HIGH 8.8
CVE-2020-15046

The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cg…

No fix yet
Fix from $1,950 2020-06-24
Blogcms HIGH 8.8
CVE-2020-15014

pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.

Fix: after 2019-12-31
Fix from $1,950 2020-06-24
Nukeviet HIGH 8.8
CVE-2020-13155

clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem…

No fix yet
Fix from $1,950 2020-06-23
Nukeviet MEDIUM 6.5
CVE-2020-13156

modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.

No fix yet
Fix from $1,600 2020-06-23
Nukeviet MEDIUM 6.5
CVE-2020-13157

modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old pas…

No fix yet
Fix from $1,600 2020-06-23
Multi Scheduler MEDIUM 6.5
CVE-2020-13426

The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibili…

No fix yet
Fix from $1,600 2020-06-22