Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Amazon Ec2 HIGH 8.8
CVE-2020-2090

A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL wit…

Fix: after 1.47
Fix from $1,950 2020-01-15
Health Advisor By Cloudbees HIGH 8.8
CVE-2020-2093

A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed…

Fix: after 3.0
Fix from $1,950 2020-01-15
Phpbb MEDIUM 6.5
CVE-2020-5502

phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.

Mitigation only
Fix from $1,600 2020-01-15
Websitebaker HIGH 8.8
CVE-2011-2934

A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmat…

Fix: after 2.8.1
Fix from $1,950 2020-01-14
Freebox Os MEDIUM 6.5
CVE-2014-9382

Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation

No fix yet
Fix from $1,600 2020-01-13
Sp C250sf Firmware HIGH 8.8
CVE-2019-14304

Ricoh SP C250DN 1.06 devices allow CSRF.

Fix: 1.02 / 1.09+
Fix from $1,950 2020-01-10
Peel Shopping MEDIUM 6.5
CVE-2019-20178

Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.

Mitigation only
Fix from $1,600 2020-01-09
Deskjet 3630 F5s43a Firmware HIGH 8.1
CVE-2019-6319

HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or h…

Mitigation only
Fix from $1,950 2020-01-09
Deskjet 3630 F5s43a Firmware HIGH 8.1
CVE-2019-6320

Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN191…

Mitigation only
Fix from $1,950 2020-01-09
Minimal Coming Soon \& Maintenance Mode HIGH 8.8
CVE-2020-6167

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, mod…

Fix: after 2.10
Fix from $1,950 2020-01-09
Snare MEDIUM 6.5
CVE-2011-5250

Snare for Linux before 1.7.0 has CSRF in the web interface.

Fix: 1.7.0+
Fix from $1,600 2020-01-08
Konakart MEDIUM 6.5
CVE-2014-5516

Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to h…

Fix: 7.3.0.0+
Fix from $1,600 2020-01-03
Satellite MEDIUM 6.5
CVE-2014-3590

Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log …

Mitigation only
Fix from $1,600 2020-01-02
Opsview HIGH 8.8
CVE-2013-3935

Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authen…

Fix: 4.4.1 / 20130522+
Fix from $1,950 2020-01-02
Zenphoto MEDIUM 6.5
CVE-2015-5595

Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin u…

Fix: 1.4.9+
Fix from $1,600 2019-12-31
Outsystems MEDIUM 6.5
CVE-2019-12273

OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted b…

Fix: after 11
Fix from $1,600 2019-12-31
Openshift MEDIUM 6.5
CVE-2013-0196

A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection me…

No fix yet
Fix from $1,600 2019-12-30
Yetishare HIGH 8.8
CVE-2019-19737

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and …

Fix: after 4.5.3
Fix from $1,950 2019-12-30
Dl4343 Firmware MEDIUM 6.5
CVE-2019-20071

On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.

No fix yet
Fix from $1,600 2019-12-30
Dwr 113 Firmware HIGH 8.8
CVE-2014-3136

Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authen…

Fix: 2.03b02+
Fix from $1,950 2019-12-27
Business Automation Software MEDIUM 6.5
CVE-2013-4665

SPBAS Business Automation Software 2012 has CSRF.

No fix yet
Fix from $1,600 2019-12-27
Dir 601 Firmware HIGH 8.8
CVE-2019-16326

D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-20…

No fix yet
Fix from $1,950 2019-12-26
Iwr 3000n Firmware HIGH 8.8
CVE-2019-19995

A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/user.

Mitigation only
Fix from $1,950 2019-12-26
Wpspellcheck HIGH 8.8
CVE-2019-6027

Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack the authentication of administr…

Fix: after 7.1.9
Fix from $1,950 2019-12-26
Custom Body Class HIGH 8.8
CVE-2019-6030

Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack the authentication of admini…

Fix: after 0.6.0
Fix from $1,950 2019-12-26
Wp Maintenance HIGH 8.8
CVE-2019-19979

A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious co…

Fix: 5.0.6+
Fix from $1,950 2019-12-26
Email Subscribers \& Newsletters MEDIUM 5.4
CVE-2019-19981

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.

Fix: 4.2.3+
Fix from $1,600 2019-12-26
Cognos Business Intelligence HIGH 8.8
CVE-2018-1934

IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Mitigation only
Fix from $1,950 2019-12-20
301 Redirects CRITICAL 9.0
CVE-2019-19915

The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or i…

Fix: 2.45+
Fix from $2,300 2019-12-19
Che HIGH 8.8
CVE-2019-17633

For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitr…

Fix: after 7.3.0
Fix from $1,950 2019-12-19