Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Altalink C8035 Firmware HIGH 8.8
CVE-2019-19832

Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserNam…

No fix yet
Fix from $1,950 2019-12-18
Tautulli MEDIUM 6.5
CVE-2019-19833EPSS 15%

In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in appl…

No fix yet
Fix from $1,600 2019-12-18
Arcsight Logger HIGH 8.8
CVE-2019-11657

Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could…

Fix: 7.0+
Fix from $1,950 2019-12-17
Alauda Kubernetes Support HIGH 8.8
CVE-2019-16575

A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-sp…

Fix: after 2.3.0
Fix from $1,950 2019-12-17
Alauda Devops Pipeline HIGH 8.8
CVE-2019-16573

A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers to connect to an attacker-spec…

Fix: after 2.3.2
Fix from $1,950 2019-12-17
Rapiddeploy HIGH 8.8
CVE-2019-16570

A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web ser…

Fix: after 4.1
Fix from $1,950 2019-12-17
Team Concert HIGH 8.8
CVE-2019-16565

A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL …

Fix: after 1.3.0
Fix from $1,950 2019-12-17
Websphere Deployer HIGH 8.8
CVE-2019-16560

A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and de…

Fix: after 1.6.1
Fix from $1,950 2019-12-17
Build Failure Analyzer HIGH 8.8
CVE-2019-16553

A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers to have Jenkins evaluate a co…

Fix: after 1.24.1
Fix from $1,950 2019-12-17
Maven HIGH 8.8
CVE-2019-16550

A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to ha…

Fix: after 0.16.1
Fix from $1,950 2019-12-17
Gerrit Trigger HIGH 8.8
CVE-2019-16551

A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified H…

Fix: after 2.30.1
Fix from $1,950 2019-12-17
Crowd MEDIUM 6.5
CVE-2017-18107

Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users…

Fix: 3.1.1+
Fix from $1,600 2019-12-17
Cloudforms HIGH 8.8
CVE-2014-0197

CFME: CSRF protection vulnerability via permissive check of the referrer header

Fix: after 5.9.3.1
Fix from $1,950 2019-12-13
Xhq HIGH 8.1
CVE-2019-13930

A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an …

Fix: 6.0.0.2+
Fix from $1,950 2019-12-12
Solismed HIGH 8.8
CVE-2019-15934

Intesync Solismed 3.3sp has CSRF.

No fix yet
Fix from $1,950 2019-12-12
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2019-0398

Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, m…

Mitigation only
Fix from $1,950 2019-12-11
Subscription Asset Manager MEDIUM 6.5
CVE-2014-0026

katello-headpin is vulnerable to CSRF in REST API

No fix yet
Fix from $1,600 2019-12-11
Nopcommerce HIGH 8.8
CVE-2019-19685

RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

No fix yet
Fix from $1,950 2019-12-09
Davical HIGH 8.8
CVE-2019-18346

A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary…

Fix: after 1.1.8
Fix from $1,950 2019-12-04
Wrn 150 Firmware MEDIUM 6.5
CVE-2019-19516EPSS 10%

Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password.

No fix yet
Fix from $1,600 2019-12-02
Amanda HIGH 8.8
CVE-2019-19469

In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with s…

Mitigation only
Fix from $1,950 2019-12-01
Octopus Deploy MEDIUM 5.3
CVE-2019-19375

In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribu…

Fix: 2019.6.14 / 2019.9.8+
Fix from $1,600 2019-11-28
Csrf Magic HIGH 8.8
CVE-2019-17590

The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the c…

Fix: after 2016-03-27
Fix from $1,950 2019-11-26
Ubuntu Linux MEDIUM 6.1
CVE-2019-18677EPSS 7%

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly inte…

Fix: after 4.8
Fix from $1,600 2019-11-26
Sd Wan Firmware MEDIUM 6.5
CVE-2019-16002

A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-…

Fix: 19.2.0+
Fix from $1,600 2019-11-26
Jboss Application Server MEDIUM 6.5
CVE-2011-3609

A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for …

Mitigation only
Fix from $1,600 2019-11-26
Dsl6740u Firmware HIGH 8.8
CVE-2013-6811

Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authenticat…

Mitigation only
Fix from $1,950 2019-11-22
Pagekit HIGH 8.8
CVE-2019-19013

A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.

No fix yet
Fix from $1,950 2019-11-22
Activity HIGH 8.8
CVE-2012-2079

A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.

Mitigation only
Fix from $1,950 2019-11-22
Synaman HIGH 8.8
CVE-2015-3140

Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, …

Mitigation only
Fix from $1,950 2019-11-21