Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Contao Cms HIGH 8.8
CVE-2019-10642

Contao 4.7 allows CSRF.

Mitigation only
Fix from $1,950 2019-04-17
GitLab MEDIUM 6.5
CVE-2019-9176

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows CSRF.

Fix: 11.6.10 / 11.7.6+
Fix from $1,600 2019-04-17
Cp 1604 Firmware MEDIUM 6.5
CVE-2018-13810

A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web server of the affected CP dev…

Fix: after 2.8
Fix from $1,600 2019-04-17
File Manager HIGH 8.8
CVE-2018-16966

There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.

No fix yet
Fix from $1,950 2019-04-15
Wp Fastest Cache HIGH 8.8
CVE-2018-17584

The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.

No fix yet
Fix from $1,950 2019-04-15
Subrion Cms HIGH 8.8
CVE-2017-18366

Subrion CMS 4.1.5 has CSRF in blog/delete/.

No fix yet
Fix from $1,950 2019-04-15
Fastadmin HIGH 8.8
CVE-2019-11077

FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI.

No fix yet
Fix from $1,950 2019-04-11
Mkcms HIGH 8.8
CVE-2019-11078

MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.

No fix yet
Fix from $1,950 2019-04-11
Airflow HIGH 8.8
CVE-2019-0229

A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site reques…

Fix: after 1.10.2
Fix from $1,950 2019-04-10
Business Automation Workflow HIGH 8.8
CVE-2018-2000

IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious…

Patch available
Fix from $1,950 2019-04-08
Ukcms HIGH 8.8
CVE-2019-10888

A CSRF Issue that can add an admin user was discovered in UKcms v1.1.10 via admin.php/admin/role/add.html.

No fix yet
Fix from $1,950 2019-04-05
Suitecrm MEDIUM 6.1
CVE-2018-20816

An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka…

Fix: 7.8.24 / 7.10.11+
Fix from $1,600 2019-04-05
Bolt HIGH 8.8
CVE-2019-10874

Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploa…

Patch available
Fix from $1,950 2019-04-05
Kmap MEDIUM 6.5
CVE-2019-10292

A cross-site request forgery vulnerability in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers to in…

Mitigation only
Fix from $1,600 2019-04-04
Openid MEDIUM 6.5
CVE-2019-1003098

A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method al…

Mitigation only
Fix from $1,600 2019-04-04
Jenkins Reviewbot MEDIUM 6.5
CVE-2019-10278

A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method a…

Mitigation only
Fix from $1,600 2019-04-04
Netsparker Cloud Scan MEDIUM 6.5
CVE-2019-10289

A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI …

Fix: after 1.1.5
Fix from $1,600 2019-04-04
Audit To Database MEDIUM 6.5
CVE-2019-1003076

A cross-site request forgery vulnerability in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form valida…

Mitigation only
Fix from $1,600 2019-04-04
Vmware Lab Manager Slaves MEDIUM 6.5
CVE-2019-1003078

A cross-site request forgery vulnerability in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validat…

Mitigation only
Fix from $1,600 2019-04-04
Openshift Deployer MEDIUM 6.5
CVE-2019-1003080

A cross-site request forgery vulnerability in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin for…

Fix: after 1.2.0
Fix from $1,600 2019-04-04
Gearman MEDIUM 6.5
CVE-2019-1003082

A cross-site request forgery vulnerability in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attack…

Mitigation only
Fix from $1,600 2019-04-04
Zephyr Enterprise Test Management MEDIUM 6.5
CVE-2019-1003084

A cross-site request forgery vulnerability in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation …

Mitigation only
Fix from $1,600 2019-04-04
Chef Sinatra MEDIUM 6.5
CVE-2019-1003086

A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form valida…

Mitigation only
Fix from $1,600 2019-04-04
Soasta Cloudtest MEDIUM 6.5
CVE-2019-1003090

A cross-site request forgery vulnerability in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method…

Mitigation only
Fix from $1,600 2019-04-04
Nomad MEDIUM 6.5
CVE-2019-1003092

A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows at…

Mitigation only
Fix from $1,600 2019-04-04
Ftp Publisher MEDIUM 6.5
CVE-2019-1003058

A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to…

Mitigation only
Fix from $1,600 2019-04-04
Ultimate Member HIGH 8.8
CVE-2019-10673

A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become adm…

Fix: 2.0.40+
Fix from $1,950 2019-04-03
Security Privileged Identity Manager HIGH 8.8
CVE-2018-1622

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute…

Mitigation only
Fix from $1,950 2019-04-02
Openshift Container Platform MEDIUM 6.3
CVE-2019-3876

A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X…

Fix: after 3.11
Fix from $1,600 2019-04-01
Omero HIGH 8.8
CVE-2014-7198

OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.

Fix: 5.0.6+
Fix from $1,950 2019-04-01