Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Gac2500 Firmware CRITICAL 9.8
CVE-2019-10655EPSS 15%

Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unau…

Fix: 1.0.3.51 / 1.0.3.219+
Fix from $2,300 2019-03-30
Hybbs HIGH 8.8
CVE-2019-10644

An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account.

No fix yet
Fix from $1,950 2019-03-30
Online Lottery Php Readymade Script HIGH 8.8
CVE-2019-9604

PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions.

No fix yet
Fix from $1,950 2019-03-29
Big Ip Application Security Manager MEDIUM 6.8
CVE-2019-6607

On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross-site scripting vulnerability…

Fix: after 14.0.0.2
Fix from $1,600 2019-03-28
Slack Notification HIGH 7.1
CVE-2019-1003044

A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified…

Fix: after 2.19
Fix from $1,950 2019-03-28
Fortify On Demand Uploader MEDIUM 6.5
CVE-2019-1003046

A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection …

Fix: after 3.0.10
Fix from $1,600 2019-03-28
S Cms HIGH 8.8
CVE-2019-10237

S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related issue to…

No fix yet
Fix from $1,950 2019-03-27
Moodle CRITICAL 10.0
CVE-2019-3809

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, w…

Fix: after 3.1.15
Fix from $2,300 2019-03-25
Ip Phone 8821 Firmware HIGH 8.8
CVE-2019-1764

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an una…

Fix: 11.0 / 12.5+
Fix from $1,950 2019-03-22
Rental Bike Script HIGH 8.8
CVE-2019-7433

PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.

No fix yet
Fix from $1,950 2019-03-21
Jiofi 4g M2s Firmware MEDIUM 6.5
CVE-2019-7440

JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcm…

No fix yet
Fix from $1,600 2019-03-21
Dsl 491hnu B10b Firmware HIGH 8.8
CVE-2019-7391EPSS 14%

ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.

No fix yet
Fix from $1,950 2019-03-21
Air 5341 Firmware HIGH 8.8
CVE-2019-6967EPSS 13%

AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.

No fix yet
Fix from $1,950 2019-03-21
Gpn2.4p21 C Cn Firmware HIGH 8.8
CVE-2019-6282

ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wls…

No fix yet
Fix from $1,950 2019-03-21
Entrepreneur Job Portal Script HIGH 8.8
CVE-2018-20641

PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.

No fix yet
Fix from $1,950 2019-03-21
Basic B2b Script HIGH 8.8
CVE-2018-20644

PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature.

No fix yet
Fix from $1,950 2019-03-21
Car Rental Script HIGH 8.8
CVE-2018-20648

PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php.

No fix yet
Fix from $1,950 2019-03-21
Advance B2b Script HIGH 8.8
CVE-2018-20633

PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.

No fix yet
Fix from $1,950 2019-03-21
Webgalamb MEDIUM 6.5
CVE-2018-19511

wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator password.

No fix yet
Fix from $1,600 2019-03-21
Cumilon Isg 600c Firmware MEDIUM 6.1
CVE-2018-19525

An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add a…

No fix yet
Fix from $1,600 2019-03-21
Layerbb MEDIUM 6.5
CVE-2018-17996

LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content v…

Patch available
Fix from $1,600 2019-03-21
Trash Bin HIGH 8.8
CVE-2018-14575

Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.

No fix yet
Fix from $1,950 2019-03-21
WordPress HIGH 8.8
CVE-2019-9787EPSS 41%

WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration…

Fix: 5.1.1+
Fix from $1,950 2019-03-14
Piluscart HIGH 8.8
CVE-2019-9769

PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.

No fix yet
Fix from $1,950 2019-03-14
Smart Forms HIGH 8.8
CVE-2019-5924

Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrat…

Fix: after 2.6.15
Fix from $1,950 2019-03-12
Formcraft HIGH 8.8
CVE-2019-5920

Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators…

Fix: after 1.2.1
Fix from $1,950 2019-03-12
Sftnow HIGH 8.8
CVE-2019-9688

sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account.

Fix: after 2018-12-29
Fix from $1,950 2019-03-11
Sdcms HIGH 8.8
CVE-2019-9652

There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and …

No fix yet
Fix from $1,950 2019-03-11
Cscms MEDIUM 6.5
CVE-2019-9598

An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.

No fix yet
Fix from $1,600 2019-03-07
Jtbc HIGH 8.8
CVE-2018-17429

/console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.

No fix yet
Fix from $1,950 2019-03-07