Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Wac120 Firmware HIGH 8.0
CVE-2018-21120

Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4…

Fix: 2.1.7 / 3.7.11.4+
Fix from $1,950 2020-04-22
R6100 Firmware HIGH 8.8
CVE-2017-18775

Certain NETGEAR devices are affected by CSRF. This affects R6100 before 1.0.1.12, R7500 before 1.0.0.108, WNDR3700v4 before 1.0.2.86, WNDR4300v1 befo…

Fix: 1.0.0.42 / 1.0.0.48+
Fix from $1,950 2020-04-22
D6200 Firmware HIGH 8.8
CVE-2017-18781

Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JWNR2010v5 befor…

Fix: 1.0.0.20 / 1.0.0.26+
Fix from $1,950 2020-04-22
D6200 Firmware HIGH 8.8
CVE-2017-18782

Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JR6150 before 1.0.1.12, JNR1010v2 before 1.…

Fix: 1.0.0.20 / 1.0.0.26+
Fix from $1,950 2020-04-22
R6050 Firmware HIGH 8.8
CVE-2017-18791

Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 before 1.0.0.17, R6220 before 1.1.0.50, WNDR3700v5 bef…

Fix: 1.0.0.17 / 1.0.1.7+
Fix from $1,950 2020-04-21
R7300 Firmware HIGH 8.8
CVE-2017-18842

Certain NETGEAR devices are affected by CSRF. This affects R7300 before 1.0.0.54, R8500 before 1.0.2.94, DGN2200v1 before 1.0.0.55, and D2200D/D2200D…

Fix: 1.0.0.32 / 1.0.0.54+
Fix from $1,950 2020-04-20
R6300 Firmware HIGH 8.8
CVE-2017-18848

Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.0.36, AC1450 before 1.0.0.36, R7300 before 1.0.0.54, and R8500 before 1…

Fix: 1.0.0.36 / 1.0.0.54+
Fix from $1,950 2020-04-20
R7300dst Firmware HIGH 8.8
CVE-2017-18852

Certain NETGEAR devices are affected by CSRF and authentication bypass. This affects R7300DST before 1.0.0.54, R8300 before 1.0.2.100_1.0.82, R8500 b…

Fix: 1.0.0.54 / 1.0.1.14+
Fix from $1,950 2020-04-20
Rukovoditel HIGH 8.8
CVE-2020-11818

In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed with another user's valid toke…

No fix yet
Fix from $1,950 2020-04-16
Dolibarr Erp\/crm HIGH 8.8
CVE-2020-11825

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in an…

No fix yet
Fix from $1,950 2020-04-16
D3600 Firmware HIGH 8.8
CVE-2019-20691

Certain NETGEAR devices are affected by CSRF. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, EX3700 before 1.0.0.70, EX3800 before 1.0.0.…

Fix: 1.0.0.22 / 1.0.0.30+
Fix from $1,950 2020-04-16
Aironet 1542i Firmware MEDIUM 6.5
CVE-2020-3261

A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a…

Fix: 8.8.130.0+
Fix from $1,600 2020-04-15
Oasis HIGH 8.1
CVE-2020-11003

Oasis before version 2.15.0 has a potential DNS rebinding or CSRF vulnerability. If you're running a vulnerable application on your computer and an a…

Fix: 2.15.0+
Fix from $1,950 2020-04-14
Provide Ftp Server HIGH 8.8
CVE-2020-11706

An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such as: Change any username and p…

Fix: after 13.1
Fix from $1,950 2020-04-12
Provide Ftp Server HIGH 8.8
CVE-2020-11701

An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonstrated by granting filesystem …

Fix: after 13.1
Fix from $1,950 2020-04-12
Management Center MEDIUM 5.9
CVE-2019-18376

A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or …

Mitigation only
Fix from $1,600 2020-04-10
Snmpc Online HIGH 8.8
CVE-2020-11553

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.

Fix: 2020-01-28+
Fix from $1,950 2020-04-09
Easyblocks Ipv6 Firmware HIGH 8.8
CVE-2020-5549

Cross-site request forgery (CSRF) vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier and Enterprise Ver. 2.0.1 and earlier allows remote attacke…

Fix: after 2.0.1
Fix from $1,950 2020-04-08
Ejbca HIGH 8.8
CVE-2020-11627

An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI.

Fix: 6.15.2.6 / 7.3.1.2+
Fix from $1,950 2020-04-08
Wp Auth0 HIGH 8.8
CVE-2020-5391

Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.

Fix: 4.0.0+
Fix from $1,950 2020-04-01
Tivoli Netcool\/impact HIGH 8.8
CVE-2020-4238

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and…

Fix: after 7.1.0.17
Fix from $1,950 2020-03-31
Tivoli Netcool\/impact HIGH 8.8
CVE-2020-4237

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and…

Fix: after 7.1.0.17
Fix from $1,950 2020-03-31
Solution Center HIGH 8.8
CVE-2015-8536

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2…

Fix: 3.3.002+
Fix from $1,950 2020-03-27
Jenkins HIGH 8.8
CVE-2020-2160

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that all…

Fix: after 2.227
Fix from $1,950 2020-03-25
Zendto HIGH 8.8
CVE-2020-8985

ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.

Mitigation only
Fix from $1,950 2020-03-24
Win Pak HIGH 8.8
CVE-2020-7005

In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker t…

Fix: 4.7.2_b1072.3.4+
Fix from $1,950 2020-03-24
Harbor HIGH 8.8
CVE-2019-19025

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.

Fix: 1.8.6 / 1.9.3+
Fix from $1,950 2020-03-20
Enigma Network Management Solution HIGH 8.8
CVE-2019-16068

A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a…

Fix: after 65.0.0
Fix from $1,950 2020-03-19
Oce Colorwave 500 Firmware HIGH 8.8
CVE-2020-10671

The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could…

Fix: after 4.0.0.0
Fix from $1,950 2020-03-19
Serv U Managed File Transfer HIGH 8.8
CVE-2019-12769

SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functi…

Fix: after 15.1.5
Fix from $1,950 2020-03-18