Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Data Center Network Manager HIGH 8.8
CVE-2020-3114

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …

Fix: 11.3+
Fix from $1,950 2020-02-19
Silverstripe HIGH 8.8
CVE-2019-12437

In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,

Fix: after 4.3.3
Fix from $1,950 2020-02-19
Icehrm HIGH 8.8
CVE-2020-9270

ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.

No fix yet
Fix from $1,950 2020-02-18
Icehrm MEDIUM 6.5
CVE-2020-9271

ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.

No fix yet
Fix from $1,600 2020-02-18
Soplanning MEDIUM 6.5
CVE-2020-9266

SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.

No fix yet
Fix from $1,600 2020-02-18
Soplanning MEDIUM 6.5
CVE-2020-9267

SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.

No fix yet
Fix from $1,600 2020-02-18
Olk Webstore HIGH 8.8
CVE-2020-6844

In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.

No fix yet
Fix from $1,950 2020-02-18
Persona HIGH 8.8
CVE-2013-4227

Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x…

Fix: 7.x-1.11+
Fix from $1,950 2020-02-18
Easy Property Listings HIGH 8.8
CVE-2020-5530

Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication …

Fix: 3.4+
Fix from $1,950 2020-02-18
Moodle MEDIUM 6.5
CVE-2020-1692

Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

Fix: 3.7.2+
Fix from $1,600 2020-02-17
Prestashop MEDIUM 5.5
CVE-2013-4792

PrestaShop before 1.4.11 allows logout CSRF.

Fix: 1.4.11+
Fix from $1,600 2020-02-14
Expedition Migration Tool HIGH 8.8
CVE-2020-1977

Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authenti…

Fix: after 1.1.51
Fix from $1,950 2020-02-12
Pipeline Github Notify Step HIGH 8.8
CVE-2020-2116

A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker…

Fix: after 1.0.4
Fix from $1,950 2020-02-12
Socialengine MEDIUM 6.3
CVE-2012-6721

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4.2.4.

Fix: 4.2.4+
Fix from $1,600 2020-02-11
Rumpus Ftp MEDIUM 5.4
CVE-2019-19667

A CSRF vulnerability exists in the Block Clients component of Web File Manager in Rumpus FTP 8.2.9.1 that could allow an attacker to whitelist or blo…

Mitigation only
Fix from $1,600 2020-02-10
Rumpus Ftp MEDIUM 6.5
CVE-2019-19669

A CSRF vulnerability exists in the Upload Center Forms Component of Web File Manager in Rumpus FTP 8.2.9.1. This could allow an attacker to delete, c…

Mitigation only
Fix from $1,600 2020-02-10
Rumpus Ftp MEDIUM 6.5
CVE-2019-19662

A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacke…

Mitigation only
Fix from $1,600 2020-02-10
Rumpus Ftp HIGH 7.1
CVE-2019-19664

A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulat…

Mitigation only
Fix from $1,950 2020-02-10
Cleanfix MEDIUM 5.4
CVE-2013-2108

WordPress WP Cleanfix Plugin 2.4.4 has CSRF

No fix yet
Fix from $1,600 2020-02-10
Wp Cleanfix HIGH 8.8
CVE-2013-2109

WordPress plugin wp-cleanfix has Remote Code Execution

No fix yet
Fix from $1,950 2020-02-10
Rumpus MEDIUM 6.5
CVE-2019-19660

A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can m…

Mitigation only
Fix from $1,600 2020-02-10
Rumpus MEDIUM 6.5
CVE-2019-19663

A CSRF vulnerability exists in the Folder Sets Settings of Web File Manager in Rumpus FTP 8.2.9.1. This allows an attacker to Create/Delete Folders a…

Mitigation only
Fix from $1,600 2020-02-10
Rumpus MEDIUM 6.5
CVE-2019-19665

A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulat…

Mitigation only
Fix from $1,600 2020-02-10
Rumpus HIGH 8.8
CVE-2019-19659

A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can tak…

Mitigation only
Fix from $1,950 2020-02-10
Yetishare HIGH 8.8
CVE-2019-20059

payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter…

Fix: after 4.5.4
Fix from $1,950 2020-02-10
Airvision Controller HIGH 8.8
CVE-2014-2225

Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the au…

Fix: 3.2.1+
Fix from $1,950 2020-02-08
Smoothwall Express HIGH 8.8
CVE-2011-1085

CSRF vulnerability in Smoothwall Express 3.

No fix yet
Fix from $1,950 2020-02-07
Load Master HIGH 8.8
CVE-2014-5288

A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.

Fix: 7.1.20b+
Fix from $1,950 2020-02-07
Linksys Wrt110 Firmware HIGH 8.8
CVE-2013-3568EPSS 25%

Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests th…

No fix yet
Fix from $1,950 2020-02-06
Dd Wrt HIGH 8.8
CVE-2012-6297

Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, whic…

No fix yet
Fix from $1,950 2020-02-06