Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Deploy Weblogic HIGH 8.8
CVE-2019-10464

A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-…

Fix: after 4.1
Fix from $1,950 2019-10-23
Kubernetes Ci HIGH 8.8
CVE-2019-10468

A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified…

Fix: after 1.3
Fix from $1,950 2019-10-23
Ad Inserter HIGH 8.8
CVE-2015-9497

The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.

Fix: 1.5.3+
Fix from $1,950 2019-10-22
Wps Hide Login HIGH 8.8
CVE-2015-9498

The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.

Fix: 1.1+
Fix from $1,950 2019-10-22
Openwrt HIGH 8.8
CVE-2019-17367

OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/for…

Patch available
Fix from $1,950 2019-10-18
2fa Enterprise Server HIGH 8.8
CVE-2019-17118

A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended ac…

Patch available
Fix from $1,950 2019-10-17
WordPress HIGH 8.8
CVE-2019-17675

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

Fix: 5.2.4+
Fix from $1,950 2019-10-17
Metinfo HIGH 8.8
CVE-2019-17676

app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, a…

No fix yet
Fix from $1,950 2019-10-17
Sf250 24 Firmware HIGH 8.8
CVE-2019-12636

A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attac…

Fix: 2.5.0.90+
Fix from $1,950 2019-10-16
Crx Content Package Deployer HIGH 8.8
CVE-2019-10437

A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attack…

Fix: after 1.8.1
Fix from $1,950 2019-10-16
Jnr1010 Firmware MEDIUM 6.5
CVE-2016-11015

NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.

Fix: 1.0.0.32+
Fix from $1,600 2019-10-16
Iwr 1000n Firmware CRITICAL 9.8
CVE-2019-17600

Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.

No fix yet
Fix from $2,300 2019-10-15
Jizhicms HIGH 8.8
CVE-2019-17593

JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.

No fix yet
Fix from $1,950 2019-10-14
Landing Cms MEDIUM 6.5
CVE-2019-17521

An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI,

No fix yet
Fix from $1,600 2019-10-12
Gree\+ HIGH 8.8
CVE-2018-20582

The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery.

No fix yet
Fix from $1,950 2019-10-11
Swagger Ui CRITICAL 9.8
CVE-2019-17495EPSS 6%

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) techniq…

Fix: 3.23.11+
Fix from $2,300 2019-10-10
Animate It\! HIGH 8.8
CVE-2019-17386

The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.

Fix: 2.3.6+
Fix from $1,950 2019-10-10
Fastadmin HIGH 8.8
CVE-2019-17431

An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.

No fix yet
Fix from $1,950 2019-10-10
Fastadmin MEDIUM 6.5
CVE-2019-17432

An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultan…

No fix yet
Fix from $1,600 2019-10-10
Sunny Webbox Firmware HIGH 8.8
CVE-2019-13529

An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the…

Fix: after 1.6
Fix from $1,950 2019-10-09
Otcms MEDIUM 6.5
CVE-2019-17369

OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superad…

No fix yet
Fix from $1,600 2019-10-09
Buddypress Activity Plus HIGH 8.1
CVE-2015-9455

The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photo…

Fix: 1.6.2+
Fix from $1,950 2019-10-07
Combi Stream Mslq Firmware HIGH 8.8
CVE-2019-17217

An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web…

Mitigation only
Fix from $1,950 2019-10-06
Youtrack HIGH 8.8
CVE-2019-15040

JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.

Fix: 2019.1+
Fix from $1,950 2019-10-02
Unified Communications Manager MEDIUM 6.5
CVE-2019-1915

A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (…

Mitigation only
Fix from $1,600 2019-10-02
Debian Linux HIGH 8.8
CVE-2019-16993

In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Pa…

Fix: after 3.1.7
Fix from $1,950 2019-09-30
Phpbb MEDIUM 6.5
CVE-2019-13376

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token…

No fix yet
Fix from $1,600 2019-09-27
Pfsense HIGH 8.8
CVE-2019-16667EPSS 55%

diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs b…

No fix yet
Fix from $1,950 2019-09-26
Unite Gallery Lite HIGH 8.8
CVE-2015-9445

The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.

Fix: 1.5+
Fix from $1,950 2019-09-26
Unite Gallery Lite MEDIUM 6.5
CVE-2015-9447

The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.

Fix: 1.5+
Fix from $1,600 2019-09-26