Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Mr1100 Firmware HIGH 8.1
CVE-2019-14526

An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a d…

Fix: 12.06.03+
Fix from $1,950 2019-08-14
Keycloak HIGH 8.8
CVE-2019-10199

It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw t…

Fix: after 6.0.1
Fix from $1,950 2019-08-14
Custom Sidebars HIGH 8.8
CVE-2017-18510

The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.

Fix: 3.1.0+
Fix from $1,950 2019-08-14
Custom Sidebars HIGH 8.8
CVE-2017-18511

The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.

Fix: 3.0.8.1+
Fix from $1,950 2019-08-14
Newsletter By Supsystic HIGH 8.8
CVE-2017-18512

The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.

Fix: 1.1.8+
Fix from $1,950 2019-08-14
Responsive Menu HIGH 8.8
CVE-2017-18513

The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.

Fix: 3.1.4+
Fix from $1,950 2019-08-14
Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv HIGH 8.8
CVE-2018-20967

The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.

Fix: 5.6.1+
Fix from $1,950 2019-08-14
Ultimate Exporter HIGH 8.8
CVE-2018-20968

The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.

Fix: 1.4.2+
Fix from $1,950 2019-08-14
Simple Fields HIGH 8.8
CVE-2013-7476

The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.

Fix: 1.2+
Fix from $1,950 2019-08-14
Wp Maps HIGH 8.8
CVE-2015-9307

The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.

Fix: 2.3.10+
Fix from $1,950 2019-08-14
Wp Maps HIGH 8.8
CVE-2015-9308

The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.

Fix: 2.3.10+
Fix from $1,950 2019-08-14
Wp Maps HIGH 8.8
CVE-2015-9309

The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.

Fix: 2.3.10+
Fix from $1,950 2019-08-14
Google Doc Embedder HIGH 8.8
CVE-2016-10882

The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.

Fix: 2.6.2+
Fix from $1,950 2019-08-14
Simple Add Pages Or Posts MEDIUM 6.5
CVE-2016-10883

The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.

Fix: 1.7+
Fix from $1,600 2019-08-14
Simple Membership HIGH 8.8
CVE-2016-10884

The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.

Fix: 3.3.3+
Fix from $1,950 2019-08-14
Wp Editor HIGH 8.8
CVE-2016-10885

The wp-editor plugin before 1.2.6 for WordPress has CSRF.

Fix: 1.2.6+
Fix from $1,950 2019-08-14
Loglogic Enterprise Virtual Appliance HIGH 8.8
CVE-2019-11207

The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contain…

Fix: after 6.2.1
Fix from $1,950 2019-08-13
Contact Form Email HIGH 8.8
CVE-2018-20964

The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.

Fix: 1.2.66+
Fix from $1,950 2019-08-13
Twitter Cards Meta HIGH 8.8
CVE-2017-18504

The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.

Fix: 2.5.0+
Fix from $1,950 2019-08-12
Wp Database Backup HIGH 8.8
CVE-2016-10874

The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.

Fix: 4.3.3+
Fix from $1,950 2019-08-12
Wp Database Backup HIGH 8.8
CVE-2016-10876

The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.

Fix: 4.3.1+
Fix from $1,950 2019-08-12
Bagisto HIGH 8.8
CVE-2019-14933

Bagisto 0.1.5 allows CSRF under /admin URIs.

No fix yet
Fix from $1,950 2019-08-11
Lightbox Plus Colorbox MEDIUM 6.1
CVE-2016-10865

The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demo…

Fix: after 2.7.2
Fix from $1,600 2019-08-09
Airstream Nas Firmware HIGH 8.8
CVE-2016-10862

Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.

No fix yet
Fix from $1,950 2019-08-08
Ew 7438rpn Mini Firmware HIGH 8.8
CVE-2016-10863

Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.

No fix yet
Fix from $1,950 2019-08-08
Cognitoys Dino Firmware MEDIUM 5.4
CVE-2017-18485

Cognitoys Dino devices allow profiles_add.html CSRF.

No fix yet
Fix from $1,600 2019-08-08
6kbbs HIGH 8.8
CVE-2015-9292

6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).

No fix yet
Fix from $1,950 2019-08-08
Import Users From Csv With Meta MEDIUM 5.7
CVE-2019-14683

The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSR…

Fix: 1.14.2.2+
Fix from $1,600 2019-08-08
Arprice Lite MEDIUM 6.5
CVE-2019-14679

core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.

No fix yet
Fix from $1,600 2019-08-08
Admin Renamer Extended MEDIUM 5.7
CVE-2019-14680

The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php …

No fix yet
Fix from $1,600 2019-08-08