Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
T6b80a Firmware HIGH 8.8
CVE-2019-6325

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) ma…

Fix: 2019-04-19 / 2019-04-26+
Fix from $1,950 2019-06-17
Azure Devops Server MEDIUM 6.5
CVE-2019-0996

A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site reque…

Patch available
Fix from $1,600 2019-06-12
Wf820\+ Lte Outdoor Cpe Firmware HIGH 8.8
CVE-2019-3410

All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems fr…

Fix: 1.0.0b06+
Fix from $1,950 2019-06-11
Jx Resources HIGH 8.8
CVE-2019-10338

A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed at…

Fix: after 1.0.36
Fix from $1,950 2019-06-11
Wampserver MEDIUM 6.5
CVE-2019-11517

WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An att…

Fix: 3.1.9+
Fix from $1,600 2019-06-10
Awk 3121 Firmware HIGH 8.8
CVE-2018-10696

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, t…

No fix yet
Fix from $1,950 2019-06-07
Industrial Network Director HIGH 8.8
CVE-2019-1881

A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to c…

Mitigation only
Fix from $1,950 2019-06-05
phpMyAdmin MEDIUM 6.5
CVE-2019-12616EPSS 19%

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin u…

Fix: 4.9.0+
Fix from $1,600 2019-06-05
Msr35 Isherlock Base HIGH 8.8
CVE-2019-9882

Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user…

Fix: 1.5.127 / 1.5.196+
Fix from $1,950 2019-06-03
Msr35 Isherlock Base HIGH 8.8
CVE-2019-9883

Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin…

Fix: 1.5.127 / 1.5.196+
Fix from $1,950 2019-06-03
Artifactory MEDIUM 6.5
CVE-2019-10324

A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStagin…

Fix: after 3.2.2
Fix from $1,600 2019-05-31
S14 Firmware HIGH 8.8
CVE-2019-12502

There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account via the /admin/access URI.

No fix yet
Fix from $1,950 2019-05-31
Ultra Elegant Ip Phone Sip T41p Firmware HIGH 8.8
CVE-2018-16218

A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote …

No fix yet
Fix from $1,950 2019-05-29
Empirecms MEDIUM 6.1
CVE-2019-12361

EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. Th…

No fix yet
Fix from $1,600 2019-05-27
Kliqqi Cms HIGH 8.8
CVE-2016-10756

Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files…

No fix yet
Fix from $1,950 2019-05-24
Readaxo HIGH 8.8
CVE-2016-10757

In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/…

No fix yet
Fix from $1,950 2019-05-24
Dr 260 Firmware MEDIUM 6.5
CVE-2018-19613

Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.

No fix yet
Fix from $1,600 2019-05-24
Computrols Building Automation Software HIGH 8.8
CVE-2019-10847

Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.

Fix: after 19.0.0
Fix from $1,950 2019-05-24
D6220 Firmware HIGH 8.8
CVE-2018-7828

A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenti…

Fix: 2.2.3.0+
Fix from $1,950 2019-05-22
My Little Forum MEDIUM 6.5
CVE-2019-12253

my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting.

Fix: 2.4.20+
Fix from $1,600 2019-05-21
Wp Booking System HIGH 7.2
CVE-2019-12239

The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require ad…

Fix: 1.5.2+
Fix from $1,950 2019-05-20
Ipbrick Os HIGH 8.8
CVE-2018-16136

An issue was discovered in the administrator interface in IPBRICK OS 6.3. The application doesn't check for Anti-CSRF tokens, allowing the submission…

No fix yet
Fix from $1,950 2019-05-13
Rt Ac3200 Firmware MEDIUM 6.5
CVE-2018-14711

Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing acti…

No fix yet
Fix from $1,600 2019-05-13
Visual Css Style Editor HIGH 8.8
CVE-2019-11886

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as…

Fix: 7.2.1+
Fix from $1,950 2019-05-13
Financial Transaction Manager HIGH 8.8
CVE-2018-1790

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an atta…

Fix: after 3.0.2.1
Fix from $1,950 2019-05-10
Metinfo HIGH 8.8
CVE-2017-12789

Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/o…

No fix yet
Fix from $1,950 2019-05-10
Metinfo MEDIUM 6.5
CVE-2017-12790

Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. …

No fix yet
Fix from $1,600 2019-05-09
Jmr1140 Firmware HIGH 8.1
CVE-2019-7746

JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and…

No fix yet
Fix from $1,950 2019-05-07
Curam Social Program Management HIGH 8.8
CVE-2018-2001

IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execut…

Fix: after 7.0.4.0
Fix from $1,950 2019-05-07
Fl Switch 3005 Firmware HIGH 8.8
CVE-2018-13993

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.

Fix: after 1.34
Fix from $1,950 2019-05-07