Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Empirecms HIGH 8.8
CVE-2018-18449

EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.

No fix yet
Fix from $1,950 2019-03-07
Nbg 418n Firmware HIGH 8.8
CVE-2019-6710

Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.

No fix yet
Fix from $1,950 2019-03-07
Njiandan Cms HIGH 8.8
CVE-2019-8437

njiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator.

Fix: after 2013-05-23
Fix from $1,950 2019-03-07
Directadmin HIGH 8.8
CVE-2019-9625

JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.

No fix yet
Fix from $1,950 2019-03-07
Minicms MEDIUM 6.5
CVE-2019-9603

MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891.

No fix yet
Fix from $1,600 2019-03-06
Iks G6824a Firmware HIGH 8.8
CVE-2019-6561

Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device.

Fix: after 4.5
Fix from $1,950 2019-03-05
Popojicms HIGH 8.8
CVE-2019-9549

An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 acco…

No fix yet
Fix from $1,950 2019-03-03
Zzzphp HIGH 8.8
CVE-2019-9182

There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the fi…

No fix yet
Fix from $1,950 2019-02-26
Online Food Ordering Script HIGH 8.0
CVE-2019-9062

PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.

No fix yet
Fix from $1,950 2019-02-23
Pluck MEDIUM 6.5
CVE-2019-9048

An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&v…

No fix yet
Fix from $1,600 2019-02-23
Pluck MEDIUM 6.5
CVE-2019-9049

An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.

No fix yet
Fix from $1,600 2019-02-23
Pluck MEDIUM 6.5
CVE-2019-9051

An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI.

No fix yet
Fix from $1,600 2019-02-23
Pluck MEDIUM 6.5
CVE-2019-9052

An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.

No fix yet
Fix from $1,600 2019-02-23
S Cms HIGH 8.8
CVE-2019-9040

S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-2018-19332.

Mitigation only
Fix from $1,950 2019-02-23
Wtcms HIGH 8.8
CVE-2019-8910

An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.

No fix yet
Fix from $1,950 2019-02-18
Icms MEDIUM 5.7
CVE-2019-8902

An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.

Fix: after 7.0.14
Fix from $1,600 2019-02-18
Manufacturing Integration And Intelligence HIGH 8.8
CVE-2019-0267

SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This…

Mitigation only
Fix from $1,950 2019-02-15
Beescms HIGH 8.8
CVE-2019-8347

BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=user URI.

No fix yet
Fix from $1,950 2019-02-15
Verydows HIGH 8.8
CVE-2019-7737

A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit.

No fix yet
Fix from $1,950 2019-02-11
C.p.sub MEDIUM 6.5
CVE-2019-7738

C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.

Fix: 5.3+
Fix from $1,600 2019-02-11
Mywebsql MEDIUM 5.7
CVE-2019-7730

MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.

No fix yet
Fix from $1,600 2019-02-11
Traq HIGH 8.8
CVE-2018-20780

Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).

No fix yet
Fix from $1,950 2019-02-11
Csz Cms HIGH 8.8
CVE-2019-7566

CSZ CMS 1.1.8 has CSRF via admin/users/new/add.

No fix yet
Fix from $1,950 2019-02-07
Doyo HIGH 8.8
CVE-2019-7569

An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admi…

No fix yet
Fix from $1,950 2019-02-07
Pbootcms MEDIUM 6.5
CVE-2019-7570

A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.

No fix yet
Fix from $1,600 2019-02-07
Monitoring MEDIUM 6.5
CVE-2019-1003022

A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads run…

Fix: after 1.74.0
Fix from $1,600 2019-02-06
Warnings HIGH 8.8
CVE-2019-1003007

A cross-site request forgery vulnerability exists in Jenkins Warnings Plugin 5.0.0 and earlier in src/main/java/hudson/plugins/warnings/GroovyParser.…

Fix: after 5.0.0
Fix from $1,950 2019-02-06
Warnings Next Generation HIGH 8.8
CVE-2019-1003008

A cross-site request forgery vulnerability exists in Jenkins Warnings Next Generation Plugin 2.1.1 and earlier in src/main/java/io/jenkins/plugins/an…

Fix: after 2.1.1
Fix from $1,950 2019-02-06
Blue Ocean MEDIUM 6.5
CVE-2019-1003012

A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-cor…

Fix: after 1.10.1
Fix from $1,600 2019-02-06
Job Import HIGH 8.8
CVE-2019-1003016

An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimp…

Fix: after 2.1
Fix from $1,950 2019-02-06