Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
One Reporter HIGH 8.8
CVE-2019-11569

Veeam ONE Reporter 9.5.0.3201 allows CSRF.

No fix yet
Fix from $1,950 2019-05-06
Airlink Es450 Firmware HIGH 8.8
CVE-2018-4066

An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially…

No fix yet
Fix from $1,950 2019-05-06
Unifi Video HIGH 8.8
CVE-2019-5430

In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration …

Fix: after 3.10.0
Fix from $1,950 2019-05-06
Twitter Kit MEDIUM 5.4
CVE-2019-5431

This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verificati…

Fix: after 3.4.0
Fix from $1,600 2019-05-06
Hx220c M5 Firmware HIGH 8.8
CVE-2019-1857

A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross…

Mitigation only
Fix from $1,950 2019-05-03
Adaptive Security Appliance Software HIGH 8.8
CVE-2019-1713

A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote atta…

Fix: 9.4.4.34 / 9.6.4.25+
Fix from $1,950 2019-05-03
Doorgets Cms HIGH 8.8
CVE-2019-11617

doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "…

No fix yet
Fix from $1,950 2019-04-30
Directadmin MEDIUM 6.1
CVE-2019-11193

The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass …

Fix: after 1.561
Fix from $1,600 2019-04-30
Intellect Core Banking HIGH 8.8
CVE-2018-14930

An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebApp/gcmsRefInsert?name=SUPP UR…

No fix yet
Fix from $1,950 2019-04-30
Smartvista HIGH 8.8
CVE-2018-15206

BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.

No fix yet
Fix from $1,950 2019-04-30
Static Analysis Utilities MEDIUM 6.5
CVE-2019-10307

A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave f…

Fix: after 1.95
Fix from $1,600 2019-04-30
Ansible Tower HIGH 8.8
CVE-2019-10310

A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doT…

Fix: after 0.9.1
Fix from $1,950 2019-04-30
Github Authentication HIGH 8.8
CVE-2019-10315

Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF.

Fix: after 0.31
Fix from $1,950 2019-04-30
Bugzilla HIGH 8.8
CVE-2018-5123

A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in al…

Fix: 4.4+
Fix from $1,950 2019-04-29
Form Maker HIGH 8.8
CVE-2019-11590

The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclu…

Fix: 1.13.5+
Fix from $1,950 2019-04-29
Contact Form HIGH 8.8
CVE-2019-11591

The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file…

Fix: 1.13.5+
Fix from $1,950 2019-04-29
Wp Form Builder HIGH 8.8
CVE-2019-11557

The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant lo…

Fix: 1.0.69+
Fix from $1,950 2019-04-26
Omniauth HIGH 8.8
CVE-2015-9284

The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails fra…

Fix: 2.0.0+
Fix from $1,950 2019-04-26
Activematrix Bpm HIGH 8.8
CVE-2019-8991

The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO A…

Fix: after 4.2.0
Fix from $1,950 2019-04-24
Activematrix Business Process Management MEDIUM 6.1
CVE-2019-11203

The workspace client, openspace client, app development client, and REST API of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM …

Fix: after 4.2.0
Fix from $1,600 2019-04-24
Gila Cms HIGH 8.8
CVE-2019-11456

Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.

No fix yet
Fix from $1,950 2019-04-22
Iwr 3000n Firmware HIGH 8.8
CVE-2019-11416

A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.

No fix yet
Fix from $1,950 2019-04-22
74cms HIGH 8.8
CVE-2019-11374EPSS 10%

74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.

No fix yet
Fix from $1,950 2019-04-20
Msvod MEDIUM 6.5
CVE-2019-11375

Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.

No fix yet
Fix from $1,600 2019-04-20
Supportassist HIGH 8.8
CVE-2019-3718

Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could po…

Fix: 3.2.0.90+
Fix from $1,950 2019-04-18
Printeron MEDIUM 6.5
CVE-2018-17168

PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page. For example, an administra…

No fix yet
Fix from $1,600 2019-04-18
GitLab HIGH 8.0
CVE-2019-10300

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation…

Fix: after 1.5.11
Fix from $1,950 2019-04-18
Xebialabs Xl Deploy MEDIUM 6.5
CVE-2019-10304

A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method …

Fix: after 7.5.3
Fix from $1,600 2019-04-18
Expressway Series MEDIUM 6.5
CVE-2019-1722

A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticat…

Mitigation only
Fix from $1,600 2019-04-18
Wireless Lan Controller Software HIGH 8.8
CVE-2019-1797

A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker…

Fix: 8.3.150.0 / 8.5.150.0+
Fix from $1,950 2019-04-18