Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Jira Server MEDIUM 6.5
CVE-2019-20401

Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished bei…

Fix: 8.5.2 / 8.6.0+
Fix from $1,600 2020-02-06
Htaccess HIGH 8.8
CVE-2020-8658EPSS 10%

The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_…

Fix: after 1.8.1
Fix from $1,950 2020-02-06
Batavi HIGH 8.8
CVE-2011-0525

Batavi before 1.0 has CSRF.

Fix: 1.0+
Fix from $1,950 2020-02-05
Planning Analytics HIGH 8.8
CVE-2019-4613

IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Mitigation only
Fix from $1,950 2020-02-05
Tutor Lms MEDIUM 6.5
CVE-2020-8615EPSS 9%

A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performin…

Fix: 1.5.3+
Fix from $1,600 2020-02-04
Phppgadmin CRITICAL 9.6
CVE-2019-10784

phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area…

Fix: after 7.12.1
Fix from $2,300 2020-02-04
Dir 100 Firmware HIGH 8.8
CVE-2013-7053

D-Link DIR-100 4.03B07: cli.cgi CSRF

No fix yet
Fix from $1,950 2020-02-04
School Management Software Php\/mysql MEDIUM 6.5
CVE-2020-8504

School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.

Fix: after 2019-03-14
Fix from $1,600 2020-01-31
School Management Software Php\/mysql MEDIUM 6.5
CVE-2020-8505

School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.

Fix: after 2019-03-14
Fix from $1,600 2020-01-31
Streaming Engine MEDIUM 6.5
CVE-2019-7654

Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be trick…

Fix: after 4.8.0
Fix from $1,600 2020-01-29
Webargs HIGH 8.8
CVE-2020-7965

flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request …

Fix: after 5.5.2
Fix from $1,950 2020-01-29
Cups Easy HIGH 8.8
CVE-2020-8424

Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.

No fix yet
Fix from $1,950 2020-01-28
Cups Easy \(purchase \& Inventory\) MEDIUM 6.5
CVE-2020-8425

Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.

No fix yet
Fix from $1,600 2020-01-28
Joomla\! HIGH 8.8
CVE-2020-8420

An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.

Fix: 3.9.15+
Fix from $1,950 2020-01-28
Rt N56u Firmware HIGH 8.8
CVE-2013-3093

ASUS RT-N56U devices allow CSRF.

Mitigation only
Fix from $1,950 2020-01-28
Code Snippets HIGH 8.8
CVE-2020-8417EPSS 12%

The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.

Fix: 2.14.0+
Fix from $1,950 2020-01-28
Joomla\! HIGH 8.8
CVE-2020-8419

An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.

Fix: 3.9.15+
Fix from $1,950 2020-01-28
Private Only HIGH 8.8
CVE-2015-5483

Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authen…

No fix yet
Fix from $1,950 2020-01-28
Veralite Firmware MEDIUM 6.5
CVE-2013-4865

Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack t…

No fix yet
Fix from $1,600 2020-01-28
Framework HIGH 8.8
CVE-2020-7991

Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.

No fix yet
Fix from $1,950 2020-01-26
Owncloud MEDIUM 6.5
CVE-2014-2050

Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authent…

Fix: 5.0.15 / 6.0.2+
Fix from $1,600 2020-01-23
Control HIGH 8.8
CVE-2019-16513

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.

No fix yet
Fix from $1,950 2020-01-23
Usebb HIGH 8.8
CVE-2011-3612

Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.

Fix: 1.0.12+
Fix from $1,950 2020-01-22
Advanced Electron Forums HIGH 8.8
CVE-2011-3582

A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive…

Fix: after 1.0.9
Fix from $1,950 2020-01-22
Marketo Forms And Tracking HIGH 8.8
CVE-2020-6849

The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.

Fix: after 1.0.2
Fix from $1,950 2020-01-21
Quay HIGH 8.8
CVE-2019-3864

A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which i…

Fix: 3.0.0+
Fix from $1,950 2020-01-21
Spring Framework MEDIUM 5.3
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc …

Fix: 5.2.3+
Fix from $1,600 2020-01-17
Serpico HIGH 8.8
CVE-2019-19854

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens to mitigate against CSRF; it…

Patch available
Fix from $1,950 2020-01-15
Pi Vision HIGH 8.8
CVE-2019-18271

OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced…

Fix: 2019+
Fix from $1,950 2020-01-15
Sounds HIGH 8.8
CVE-2020-2098

A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user a…

Fix: after 0.5
Fix from $1,950 2020-01-15