Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Nexus 543 Firmware HIGH 8.8
CVE-2013-3312

Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of u…

No fix yet
Fix from $1,950 2019-11-21
Google Compute Engine HIGH 8.8
CVE-2019-16548

A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used …

Fix: 4.2.0+
Fix from $1,950 2019-11-21
Cobbler HIGH 8.8
CVE-2011-4952

cobbler: Web interface lacks CSRF protection when using Django framework

Mitigation only
Fix from $1,950 2019-11-19
Infinias Access Control Firmware MEDIUM 6.5
CVE-2019-18651

A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious …

Fix: after 6.6.9586.0
Fix from $1,600 2019-11-14
Tew 812dru Firmware HIGH 8.8
CVE-2013-3366

Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24M…

Mitigation only
Fix from $1,950 2019-11-13
Rise Ultimate Project Manager HIGH 8.8
CVE-2019-18884

index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.

No fix yet
Fix from $1,950 2019-11-13
Wnr3500u Firmware MEDIUM 6.5
CVE-2013-3516

NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF toke…

No fix yet
Fix from $1,600 2019-11-13
Debian Linux MEDIUM 6.5
CVE-2012-4385

letodms 3.3.6 has CSRF via change password

No fix yet
Fix from $1,600 2019-11-13
Pixelpost HIGH 8.8
CVE-2010-3305

Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.

No fix yet
Fix from $1,950 2019-11-12
Igniteup HIGH 8.8
CVE-2019-17237

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.

Fix: after 3.4
Fix from $1,950 2019-11-12
Manageengine Adselfservice Plus HIGH 8.8
CVE-2019-18411

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability…

Mitigation only
Fix from $1,950 2019-11-06
Joomla\! HIGH 8.8
CVE-2019-18650

An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.

Fix: after 3.9.12
Fix from $1,950 2019-11-06
Magento HIGH 8.0
CVE-2019-8109

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft …

Fix: 2.2.10 / 2.3.2+
Fix from $1,950 2019-11-05
Debian Linux MEDIUM 6.5
CVE-2013-6275

Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.

Fix: after 5.1.2
Fix from $1,600 2019-11-05
Debian Linux HIGH 8.8
CVE-2013-6364

Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

No fix yet
Fix from $1,950 2019-11-05
Debian Linux MEDIUM 5.3
CVE-2013-6365

Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions

Patch available
Fix from $1,600 2019-11-05
Cloud Access Manager MEDIUM 6.5
CVE-2019-13497

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

Fix: 8.1.4+
Fix from $1,600 2019-11-04
Infobusiness HIGH 8.8
CVE-2019-18206

A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.

Fix: after 4.4.1
Fix from $1,950 2019-10-30
Labkey Server HIGH 8.8
CVE-2019-9926

An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptRepor…

No fix yet
Fix from $1,950 2019-10-29
Tikiwiki Cms\/groupware HIGH 8.8
CVE-2010-4241

Tiki Wiki CMS Groupware 5.2 has CSRF

No fix yet
Fix from $1,950 2019-10-28
Tl Wdr4300 Firmware HIGH 8.8
CVE-2013-4848

TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.

No fix yet
Fix from $1,950 2019-10-25
Experience Manager MEDIUM 6.5
CVE-2019-8234

Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive i…

Mitigation only
Fix from $1,600 2019-10-25
Groupware HIGH 8.8
CVE-2019-12095

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags para…

Fix: after 5.2.22
Fix from $1,950 2019-10-24
Restaurant Management System HIGH 8.8
CVE-2019-18414

Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF…

No fix yet
Fix from $1,950 2019-10-24
Enterprise Immune System MEDIUM 6.5
CVE-2019-9596

Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.

Fix: 3.1+
Fix from $1,600 2019-10-23
Enterprise Immune System MEDIUM 6.5
CVE-2019-9597

Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.

Fix: 3.1+
Fix from $1,600 2019-10-23
Sitemagic HIGH 8.8
CVE-2019-18220

Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowi…

Mitigation only
Fix from $1,950 2019-10-23
Online Grading System HIGH 8.8
CVE-2019-18280

Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead …

No fix yet
Fix from $1,950 2019-10-23
Libvirt Slaves HIGH 8.8
CVE-2019-10471

A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using att…

Fix: after 1.8.5
Fix from $1,950 2019-10-23
Dynatrace Application Monitoring HIGH 8.1
CVE-2019-10462

A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an at…

Fix: after 2.1.3
Fix from $1,950 2019-10-23