Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Salesiq HIGH 8.8
CVE-2019-5963

Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrat…

Fix: after 1.0.8
Fix from $1,950 2019-07-05
Big Ip Advanced Firewall Manager HIGH 8.4
CVE-2019-6636

On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability…

Fix: 12.1.4.1 / 13.1.1.5+
Fix from $1,950 2019-07-03
Youtrack HIGH 8.8
CVE-2019-12851

A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.

Fix: 2018.4.49852+
Fix from $1,950 2019-07-03
Nexpose HIGH 8.8
CVE-2019-5630

A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue al…

Fix: after 6.5.68
Fix from $1,950 2019-07-03
Ox Guard HIGH 8.8
CVE-2018-10986

OX Guard 2.8.0 has CSRF.

Mitigation only
Fix from $1,950 2019-07-03
Oncell G3150 Hspa Firmware HIGH 8.8
CVE-2018-11427

CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to per…

Fix: after 1.4
Fix from $1,950 2019-07-03
Dcs 1130 Firmware HIGH 8.8
CVE-2017-8406

An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. …

No fix yet
Fix from $1,950 2019-07-02
Dcs 1130 Firmware HIGH 8.8
CVE-2017-8407

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the we…

No fix yet
Fix from $1,950 2019-07-02
Linear Emerge Essential Firmware HIGH 8.8
CVE-2019-7262EPSS 16%

Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).

Fix: after 1.00-06
Fix from $1,950 2019-07-02
Linear Emerge 50p Firmware HIGH 8.8
CVE-2019-7270

Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).

Fix: after 4.6.07
Fix from $1,950 2019-07-02
Cyberpanel HIGH 8.8
CVE-2019-13056

An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of t…

Fix: after 1.8.4
Fix from $1,950 2019-07-02
Enterprise HIGH 8.8
CVE-2019-7273

Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).

Fix: after 2.3.0a
Fix from $1,950 2019-07-01
Flexair HIGH 8.8
CVE-2019-7281

Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform …

Fix: after 2.3.38
Fix from $1,950 2019-07-01
Widget Logic HIGH 8.8
CVE-2019-12826

A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote a…

Fix: 5.10.2+
Fix from $1,950 2019-07-01
Peel Shopping HIGH 8.8
CVE-2018-20848

Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleu…

No fix yet
Fix from $1,950 2019-06-30
Chrome MEDIUM 6.5
CVE-2019-5814

Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HT…

Fix: 74.0.3729.108+
Fix from $1,600 2019-06-27
Service Bridge HIGH 8.8
CVE-2019-6166

A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.

Fix: 4.1.0.1+
Fix from $1,950 2019-06-26
Api Connect HIGH 8.8
CVE-2018-1858

IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Fix: after 5.0.8.6
Fix from $1,950 2019-06-25
Espressreport Enterprise Server HIGH 8.8
CVE-2019-9958

CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin acc…

No fix yet
Fix from $1,950 2019-06-24
Jeditor HIGH 8.8
CVE-2019-12836

The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to …

Fix: 3.0.6+
Fix from $1,950 2019-06-21
Ios Xe HIGH 8.8
CVE-2019-1904

A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request…

Mitigation only
Fix from $1,950 2019-06-21
Prime Service Catalog HIGH 8.8
CVE-2019-1874

A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to cond…

Patch available
Fix from $1,950 2019-06-20
Integrated Management Controller HIGH 8.0
CVE-2019-1632

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker t…

Mitigation only
Fix from $1,950 2019-06-20
Nimble Professional HIGH 8.8
CVE-2018-17387

CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.

No fix yet
Fix from $1,950 2019-06-19
Live Call Support HIGH 8.8
CVE-2018-17389

CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.

No fix yet
Fix from $1,950 2019-06-19
Almond 2015 Firmware HIGH 8.8
CVE-2017-8328

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of…

No fix yet
Fix from $1,950 2019-06-18
Almond 2015 Firmware HIGH 8.0
CVE-2017-8334

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of…

No fix yet
Fix from $1,950 2019-06-18
Welcome To Our Resort HIGH 8.8
CVE-2018-18802

The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit.

No fix yet
Fix from $1,950 2019-06-18
Cloud Private HIGH 8.8
CVE-2019-4142

IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u…

Fix: after 2.1.0.3
Fix from $1,950 2019-06-18
Veraedge Firmware HIGH 8.8
CVE-2017-9381

An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a user with the capability of installing or deletin…

Fix: after 1.7.481
Fix from $1,950 2019-06-17