Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Flatcore HIGH 8.8
CVE-2019-13961

A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.

Fix: 1.5+
Fix from $1,950 2019-07-18
Oecms HIGH 8.8
CVE-2019-1010112

OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator accou…

No fix yet
Fix from $1,950 2019-07-18
Syguestbook A5 HIGH 8.8
CVE-2019-13949

SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.

No fix yet
Fix from $1,950 2019-07-18
Mediant 500l Msbr Firmware HIGH 8.8
CVE-2019-9231

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cr…

Mitigation only
Fix from $1,950 2019-07-18
Dolibarr Erp\/crm HIGH 8.8
CVE-2019-1010054

Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disa…

No fix yet
Fix from $1,950 2019-07-18
Domainmod HIGH 8.8
CVE-2019-1010094

domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change admin password. The…

No fix yet
Fix from $1,950 2019-07-18
Domainmod HIGH 8.8
CVE-2019-1010095

DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator acco…

No fix yet
Fix from $1,950 2019-07-18
Domainmod HIGH 8.8
CVE-2019-1010096

DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user …

No fix yet
Fix from $1,950 2019-07-18
Jenkins HIGH 7.5
CVE-2019-10353

CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF prote…

Fix: after 2.185
Fix from $1,950 2019-07-17
Python Engineio HIGH 8.8
CVE-2019-13611

An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to ma…

Fix: after 3.8.2
Fix from $1,950 2019-07-16
Saleor HIGH 8.8
CVE-2019-13594

In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request withou…

Mitigation only
Fix from $1,950 2019-07-14
Dir 655 Firmware HIGH 8.8
CVE-2019-13563

D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.

No fix yet
Fix from $1,950 2019-07-11
Mybb 2fa HIGH 8.8
CVE-2019-12363

An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a request to an installed mybb2fa plu…

Fix: after 2014-11-05
Fix from $1,950 2019-07-11
Docker HIGH 8.8
CVE-2019-10340

A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with…

Fix: after 1.1.6
Fix from $1,950 2019-07-11
Debian Linux HIGH 8.8
CVE-2019-12466

Wikimedia MediaWiki through 1.32.1 allows CSRF.

Fix: after 1.32.1
Fix from $1,950 2019-07-10
Powerpanel HIGH 8.8
CVE-2019-13071

CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web…

No fix yet
Fix from $1,950 2019-07-10
Eventum HIGH 8.8
CVE-2018-12628

An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privileges.

Fix: after 3.5.0
Fix from $1,950 2019-07-10
Mailenable MEDIUM 6.5
CVE-2019-12923

In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was…

Fix: 6.90 / 7.62+
Fix from $1,600 2019-07-08
Fcm Mb40 Firmware HIGH 8.8
CVE-2019-13401

Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.

No fix yet
Fix from $1,950 2019-07-08
Flarum HIGH 8.8
CVE-2019-13183

Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.

Mitigation only
Fix from $1,950 2019-07-07
Ignitedcms HIGH 8.8
CVE-2019-13370

index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.

Fix: after 2017-02-19
Fix from $1,950 2019-07-06
Custom Css Pro HIGH 8.8
CVE-2019-5984

Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack the authentication of administr…

Fix: after 1.0.3
Fix from $1,950 2019-07-05
Growi HIGH 8.8
CVE-2019-5968

Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators vi…

Fix: after 3.4.6
Fix from $1,950 2019-07-05
Attendance Manager HIGH 8.8
CVE-2019-5971

Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijack the authentication of admin…

Fix: after 0.5.6
Fix from $1,950 2019-07-05
Online Lesson Booking HIGH 8.8
CVE-2019-5973

Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hijack the authentication of ad…

Fix: after 0.8.6
Fix from $1,950 2019-07-05
Contest Gallery HIGH 8.8
CVE-2019-5974

Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of a…

Fix: 10.4.5+
Fix from $1,950 2019-07-05
Personalized Woocommerce Cart Page HIGH 8.8
CVE-2019-5979

Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentic…

Fix: after 2.4
Fix from $1,950 2019-07-05
Related Youtube Videos HIGH 8.8
CVE-2019-5980

Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authenticatio…

Fix: 1.9.9+
Fix from $1,950 2019-07-05
Html5 Maps HIGH 8.8
CVE-2019-5983

Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrat…

Fix: after 1.6.5.6
Fix from $1,950 2019-07-05
Wp Open Graph HIGH 8.8
CVE-2019-5960

Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the authentication of administra…

Fix: after 1.6.1
Fix from $1,950 2019-07-05