Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Webfocus Business Intelligence HIGH 8.8
CVE-2020-14203

WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServle…

No fix yet
Fix from $1,950 2020-06-22
Woocommerce HIGH 8.8
CVE-2019-20891

WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scr…

Fix: 3.6.5+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2016-11084

An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.

Fix: 2.1.0+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 8.8
CVE-2017-18903

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.

Fix: 3.9.2 / 3.10.2+
Fix from $1,950 2020-06-19
Rails MEDIUM 6.5
CVE-2020-8167

A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

Fix: 5.2.4.3 / 6.0.3.1+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 8.8
CVE-2019-20865

An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF.

Fix: 4.10.10 / 5.9.2+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 8.8
CVE-2019-20841

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for ac…

Fix: 5.9.7 / 5.15.4+
Fix from $1,950 2020-06-19
Rbk752 Firmware HIGH 8.8
CVE-2020-14432

Certain NETGEAR devices are affected by CSRF. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before …

Fix: 3.2.15.25+
Fix from $1,950 2020-06-18
Easergy T300 Firmware HIGH 8.8
CVE-2020-7503

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to…

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Wpforo HIGH 8.8
CVE-2019-19109

The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.

No fix yet
Fix from $1,950 2020-06-15
Couchbase Server HIGH 8.8
CVE-2020-9042

In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the…

Mitigation only
Fix from $1,950 2020-06-08
Comments MEDIUM 6.5
CVE-2020-13868

An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.

Fix: 1.5.5+
Fix from $1,600 2020-06-05
Nextgen Dvr Firmware MEDIUM 6.5
CVE-2020-11682

Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included…

No fix yet
Fix from $1,600 2020-06-04
Dir 865l Firmware HIGH 8.8
CVE-2020-13786

D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.

No fix yet
Fix from $1,950 2020-06-03
Selenium HIGH 8.0
CVE-2020-2196

Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions …

Fix: after 3.141.59
Fix from $1,950 2020-06-03
Self Organizing Swarm Modules MEDIUM 6.5
CVE-2020-2192

A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove…

Fix: after 3.20
Fix from $1,600 2020-06-03
Joomla\! HIGH 8.8
CVE-2020-13760

In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.

Fix: 3.9.19+
Fix from $1,950 2020-06-02
Lexiglot HIGH 8.8
CVE-2014-8942

Lexiglot through 2014-11-20 allows CSRF.

Fix: after 2014-11-20
Fix from $1,950 2020-06-01
Crucible HIGH 8.8
CVE-2020-4018

The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site req…

Fix: 4.8.1+
Fix from $1,950 2020-06-01
Page Builder HIGH 8.8
CVE-2020-13643

An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification…

Fix: 2.10.16+
Fix from $1,950 2020-05-28
Real Time Find And Replace HIGH 8.8
CVE-2020-13641

An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verif…

Fix: 4.0.2+
Fix from $1,950 2020-05-28
Page Builder HIGH 8.8
CVE-2020-13642

An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce …

Fix: 2.10.16+
Fix from $1,950 2020-05-28
Airos HIGH 8.8
CVE-2020-8168

We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.…

Fix: after 6.2.0
Fix from $1,950 2020-05-26
Image Resizer HIGH 8.8
CVE-2020-13458

An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.

Fix: 2.0.9+
Fix from $1,950 2020-05-25
Controller HIGH 8.8
CVE-2020-13412

An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, lead…

Fix: 5.4.1204+
Fix from $1,950 2020-05-22
Controller MEDIUM 6.5
CVE-2020-13416

An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, wh…

Fix: 5.4.1066+
Fix from $1,600 2020-05-22
Sharepoint Enterprise Server MEDIUM 6.5
CVE-2020-1103

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site…

Patch available
Fix from $1,600 2020-05-21
Gila Cms HIGH 8.8
CVE-2019-20804

Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.

Fix: 1.11.6+
Fix from $1,950 2020-05-21
Fedora MEDIUM 6.5
CVE-2020-13231

In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.

Fix: 1.2.11+
Fix from $1,600 2020-05-20
Infosphere Information Server MEDIUM 6.5
CVE-2020-4286

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious…

Patch available
Fix from $1,600 2020-05-19