Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Rconfig HIGH 8.8
CVE-2020-12257

rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF token. An attacker…

No fix yet
Fix from $1,950 2020-05-18
Subrion HIGH 8.1
CVE-2019-20390

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server wit…

No fix yet
Fix from $1,950 2020-05-15
Movable Type HIGH 8.8
CVE-2020-5576

Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Adva…

Fix: after 7.2.1
Fix from $1,950 2020-05-14
TYPO3 HIGH 8.8
CVE-2020-11069

In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable t…

Fix: after 10.4.1
Fix from $1,950 2020-05-14
Wd Discovery HIGH 8.8
CVE-2020-12427

The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealin…

Fix: 3.8.229+
Fix from $1,950 2020-05-13
Glpi HIGH 8.8
CVE-2020-11060EPSS 11%

In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited…

Fix: 9.4.6+
Fix from $1,950 2020-05-12
Tcexam HIGH 7.4
CVE-2020-5745

Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into click…

Patch available
Fix from $1,950 2020-05-07
Action Rf 1200 Firmware HIGH 8.8
CVE-2019-19517

Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.

No fix yet
Fix from $1,950 2020-05-05
5209r Firmware MEDIUM 6.5
CVE-2020-5517

CSRF in the /login URI in BlueOnyx 5209R allows an attacker to access the dashboard and perform scraping or other analysis.

Patch available
Fix from $1,600 2020-05-05
Ruckus Zoneflex R500 Firmware HIGH 8.1
CVE-2020-7983

A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks.

No fix yet
Fix from $1,950 2020-05-05
Cip 92200 Firmware HIGH 8.8
CVE-2020-8829

CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.

No fix yet
Fix from $1,950 2020-05-05
Ruckus Zoneflex R500 Firmware HIGH 8.8
CVE-2020-8830

CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field …

No fix yet
Fix from $1,950 2020-05-05
Archer HIGH 8.8
CVE-2020-5335

RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potential…

Fix: 6.7.0.2+
Fix from $1,950 2020-05-04
Debian Linux MEDIUM 6.5
CVE-2020-12626

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not consid…

Fix: 1.4.4+
Fix from $1,600 2020-05-04
Ofbiz HIGH 8.8
CVE-2019-0235EPSS 33%

Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

No fix yet
Fix from $1,950 2020-04-30
Ninja Forms MEDIUM 6.1
CVE-2020-12462

The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.

Fix: 3.4.24.2+
Fix from $1,600 2020-04-29
Readynas Surveillance HIGH 8.0
CVE-2017-18861

Certain NETGEAR devices are affected by CSRF. This affects ReadyNAS Surveillance 1.4.3-15-x86 and earlier and ReadyNAS Surveillance 1.1.4-5-ARM and e…

Fix: after 1.4.3-15
Fix from $1,950 2020-04-28
Wac120 Firmware HIGH 7.4
CVE-2018-21096

Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4…

Fix: 2.1.7 / 3.7.11.4+
Fix from $1,950 2020-04-27
Cloud App Management HIGH 8.8
CVE-2019-4750

IBM Cloud App Management 2019.3.0 and 2019.4.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and una…

Mitigation only
Fix from $1,950 2020-04-24
D1500 Firmware HIGH 8.8
CVE-2017-18703

Certain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.25, D6100 before 1.0.0.55, D7000 before 1.0.1.50,…

Fix: 1.0.0.25 / 1.0.0.55+
Fix from $1,950 2020-04-24
R8300 Firmware HIGH 8.8
CVE-2017-18708

Certain NETGEAR devices are affected by CSRF. This affects R8300 before 1.0.2.94 and R8500 before 1.0.2.94.

Fix: 1.0.2.94+
Fix from $1,950 2020-04-24
Readynas Os HIGH 8.8
CVE-2018-21160

NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.

Fix: 6.9.3+
Fix from $1,950 2020-04-23
Readynas Os Firmware HIGH 8.8
CVE-2018-21102

NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.

Fix: 6.9.3+
Fix from $1,950 2020-04-23
Jr6150 Firmware HIGH 8.8
CVE-2017-18742

Certain NETGEAR devices are affected by CSRF. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10, R6250 before 1.0.4.12, R6300v2 before 1.0.4…

Fix: 1.0.0.54 / 1.0.1.10+
Fix from $1,950 2020-04-23
Jnr1010 Firmware HIGH 8.8
CVE-2017-18749

Certain NETGEAR devices are affected by CSRF. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, R6050 befor…

Fix: 1.0.0.112 / 1.0.1.10+
Fix from $1,950 2020-04-23
Data Tables Generator HIGH 8.8
CVE-2020-12076

The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored…

Fix: 1.9.92+
Fix from $1,950 2020-04-23
Phantompdf HIGH 8.8
CVE-2020-10890

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is r…

Fix: after 9.7.1.29511
Fix from $1,950 2020-04-22
Phantompdf HIGH 8.8
CVE-2020-10892

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is r…

Fix: after 9.7.1.29511
Fix from $1,950 2020-04-22
R6300 Firmware HIGH 8.8
CVE-2017-18755

Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.4.8, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1…

Fix: 1.0.0.54 / 1.0.0.56+
Fix from $1,950 2020-04-22
Ex6100 Firmware HIGH 8.8
CVE-2017-18768

Certain NETGEAR devices are affected by CSRF. This affects EX6100 before 1.0.2.16_1.1.130, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.54, EX6200…

Fix: 1.0.1.50 / 1.0.1.54+
Fix from $1,950 2020-04-22