Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Subrion HIGH 8.8
CVE-2018-21037

Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.

Fix: after 4.1.5
Fix from $1,950 2020-03-17
Manageengine Password Manager Pro HIGH 8.8
CVE-2020-9346

Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changin…

Fix: 10.4+
Fix from $1,950 2020-03-16
Nagios HIGH 8.8
CVE-2020-6585

Nagios Log Server 2.1.3 has CSRF.

No fix yet
Fix from $1,950 2020-03-16
Joomla\! HIGH 8.8
CVE-2020-10241

An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.

Fix: 3.9.16+
Fix from $1,950 2020-03-16
Sitepress Multilingual Cms HIGH 8.8
CVE-2020-10568

The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution i…

Fix: 4.3.7+
Fix from $1,950 2020-03-14
Ecosys M5526cdw Firmware MEDIUM 6.5
CVE-2019-13199

Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this v…

Mitigation only
Fix from $1,600 2020-03-13
Phaser 3320 Firmware MEDIUM 6.5
CVE-2019-13170

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this v…

Mitigation only
Fix from $1,600 2020-03-13
Cg3700b Firmware HIGH 8.8
CVE-2019-13395

The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA…

No fix yet
Fix from $1,950 2020-03-13
Webuntis HIGH 8.8
CVE-2020-10540

Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.

Fix: 2020.9.6+
Fix from $1,950 2020-03-13
Fortisiem HIGH 8.8
CVE-2019-17653

A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to…

Mitigation only
Fix from $1,950 2020-03-12
Phpkb MEDIUM 6.5
CVE-2020-10501

CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted req…

No fix yet
Fix from $1,600 2020-03-12
Phpkb MEDIUM 6.5
CVE-2020-10497

CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a category via a crafted request.

No fix yet
Fix from $1,600 2020-03-12
Phpkb MEDIUM 6.5
CVE-2020-10498

CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.

No fix yet
Fix from $1,600 2020-03-12
Phpkb HIGH 8.8
CVE-2020-10478

CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code …

No fix yet
Fix from $1,950 2020-03-12
Enhanced Multimedia Router Firmware CRITICAL 9.8
CVE-2020-10181 KEVEPSS 15%

goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) …

Mitigation only
Fix from $2,300 2020-03-11
Registrationmagic HIGH 8.8
CVE-2020-9454

A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site admi…

Fix: after 4.6.0.3
Fix from $1,950 2020-03-06
Centreon HIGH 8.8
CVE-2019-17642

An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharac…

Fix: 18.10.8 / 19.04.2+
Fix from $1,950 2020-03-05
Genixcms HIGH 8.8
CVE-2020-10057

GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2…

No fix yet
Fix from $1,950 2020-03-04
Prime Network Registrar HIGH 7.1
CVE-2020-3148

A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross…

Fix: 10.1+
Fix from $1,950 2020-03-04
Phpipam HIGH 8.8
CVE-2020-7988

An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privil…

No fix yet
Fix from $1,950 2020-03-04
Wnr1000 Firmware HIGH 8.8
CVE-2019-20487

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unau…

Mitigation only
Fix from $1,950 2020-03-02
Atutor HIGH 8.8
CVE-2015-1583

Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for re…

Patch available
Fix from $1,950 2020-03-02
Cf Deployment HIGH 8.8
CVE-2020-5402

In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback func…

Fix: 12.33.0 / 74.14.0+
Fix from $1,950 2020-02-27
Puppet Enterprise HIGH 8.8
CVE-2015-5686

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would all…

Fix: 2015.2.0+
Fix from $1,950 2020-02-27
Visual Access Manager MEDIUM 6.5
CVE-2019-19987

An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any HTML form. An …

Fix: after 4.29.0
Fix from $1,600 2020-02-26
Pricing Table By Supsystic HIGH 8.8
CVE-2020-9394

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.

Fix: 1.8.2+
Fix from $1,950 2020-02-25
Litecart MEDIUM 5.3
CVE-2020-9018

LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.

Fix: after 2.2.1
Fix from $1,600 2020-02-25
Xgw 3000 Zigbee Gateway Firmware HIGH 8.8
CVE-2019-20480

In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbi…

Fix: 2.4.0+
Fix from $1,950 2020-02-24
Candidats HIGH 8.8
CVE-2020-9341

CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.

No fix yet
Fix from $1,950 2020-02-22
Axous HIGH 8.8
CVE-2012-2629

Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack…

Fix: after 1.1.1
Fix from $1,950 2020-02-20