Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Deny All Firewall HIGH 8.8
CVE-2019-14681

The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF.

Fix: 1.1.7+
Fix from $1,950 2019-08-08
Hyperflex Hx Data Platform HIGH 8.8
CVE-2019-1958

A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-…

Fix: 4.0+
Fix from $1,950 2019-08-08
Xl Testview HIGH 8.8
CVE-2019-10386

A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows use…

Fix: after 1.2.0
Fix from $1,950 2019-08-07
Jclouds HIGH 8.8
CVE-2019-10368

A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JClouds…

Fix: after 2.14
Fix from $1,950 2019-08-07
Airstream Nas Firmware MEDIUM 6.5
CVE-2016-10861

Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password.

Mitigation only
Fix from $1,600 2019-08-07
Mdc N4090 Firmware HIGH 8.8
CVE-2019-14703

A CSRF issue was discovered in webparam?user&action=set&param=add in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 to creat…

Fix: after 6400.0.8.5
Fix from $1,950 2019-08-06
Adive HIGH 8.8
CVE-2019-14346

Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.

No fix yet
Fix from $1,950 2019-08-06
Das Q Software CRITICAL 9.8
CVE-2019-14551

Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin /install request with an att…

Fix: 3.2.5+
Fix from $2,300 2019-08-03
Magento MEDIUM 6.5
CVE-2019-7947

A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commer…

Fix: 1.9.4.2 / 1.14.4.2+
Fix from $1,600 2019-08-02
Magento MEDIUM 6.5
CVE-2019-7874

A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can re…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento HIGH 8.8
CVE-2019-7865

A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magent…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento MEDIUM 6.5
CVE-2019-7851

A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to uninten…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Openshift Container Platform MEDIUM 5.4
CVE-2019-10176

A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found …

Mitigation only
Fix from $1,600 2019-08-02
Windu Cms HIGH 8.8
CVE-2013-7473

Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.

No fix yet
Fix from $1,950 2019-08-01
Openstack HIGH 8.8
CVE-2018-10899

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly c…

Fix: 1.6.1+
Fix from $1,950 2019-08-01
Moodle HIGH 8.8
CVE-2019-10186

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.

Fix: 3.5.7 / 3.6.5+
Fix from $1,950 2019-07-31
Wallacepos HIGH 8.8
CVE-2019-3959

Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into cl…

Patch available
Fix from $1,950 2019-07-31
Draytekl Firmware MEDIUM 6.5
CVE-2018-20872

DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.

Fix: 2018-05-23+
Fix from $1,600 2019-07-31
M2release MEDIUM 6.3
CVE-2019-10359

A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attacker…

Fix: after 0.14.0
Fix from $1,600 2019-07-31
Custom Simple Rss MEDIUM 6.5
CVE-2019-14327

A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings.

Fix: after 2.0.6
Fix from $1,600 2019-07-30
Edx Platform HIGH 8.8
CVE-2016-10766

edx-platform before 2016-06-06 allows CSRF.

Fix: 2016-06-06+
Fix from $1,950 2019-07-29
Simple Membership HIGH 8.8
CVE-2019-14328

The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.

Fix: 3.8.5+
Fix from $1,950 2019-07-28
Xavier MEDIUM 6.1
CVE-2019-14228

Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/ad…

No fix yet
Fix from $1,600 2019-07-26
Qradar Security Information And Event Manager HIGH 8.8
CVE-2019-4212

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions t…

Fix: 7.2.8 / 7.3.2+
Fix from $1,950 2019-07-25
Firefox HIGH 8.8
CVE-2019-11712

POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attac…

Fix: 60.8.0 / 68.0+
Fix from $1,950 2019-07-23
Wcms HIGH 8.1
CVE-2019-14240

WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.

Mitigation only
Fix from $1,950 2019-07-23
Wp Code Highlightjs HIGH 8.8
CVE-2019-12934

An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows …

Fix: after 0.6.2
Fix from $1,950 2019-07-20
Mdaemon Webmail HIGH 8.8
CVE-2018-17792

MDaemon Webmail (formerly WorldClient) has CSRF.

No fix yet
Fix from $1,950 2019-07-19
Layerbb HIGH 8.8
CVE-2019-13974

LayerBB 1.1.3 allows conversations.php/cmd/new CSRF.

Patch available
Fix from $1,950 2019-07-19
Experience Manager MEDIUM 6.5
CVE-2019-7953

Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Info…

Fix: after 6.4
Fix from $1,600 2019-07-18