Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Job Import MEDIUM 5.3
CVE-2019-1003017

A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from…

Fix: after 3.0
Fix from $1,600 2019-02-06
Phpmywind MEDIUM 6.1
CVE-2019-7402

An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be explo…

No fix yet
Fix from $1,600 2019-02-05
Sente HIGH 8.8
CVE-2019-1000022

Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can re…

Fix: 1.14.0+
Fix from $1,950 2019-02-04
Mapsvg Lite HIGH 8.8
CVE-2019-1000003

MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_s…

No fix yet
Fix from $1,950 2019-02-04
Zoneminder HIGH 8.8
CVE-2019-7346

A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button,…

Fix: after 1.32.3
Fix from $1,950 2019-02-04
Epolicy Orchestrator HIGH 8.8
CVE-2019-3604

Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an …

Mitigation only
Fix from $1,950 2019-02-01
Cscms HIGH 8.1
CVE-2019-6779

Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.

No fix yet
Fix from $1,950 2019-01-24
Unified Intelligence Center HIGH 7.4
CVE-2019-1658

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct…

Mitigation only
Fix from $1,950 2019-01-24
Airflow HIGH 8.8
CVE-2017-17835

In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.

Fix: after 1.8.2
Fix from $1,950 2019-01-23
Insight HIGH 8.8
CVE-2019-6507

An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allows CSRF.

Fix: after 2018-09-11
Fix from $1,950 2019-01-22
Insight HIGH 8.8
CVE-2019-6508

An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allows CSRF.

Fix: after 2018-09-11
Fix from $1,950 2019-01-22
Insight HIGH 8.8
CVE-2019-6509

An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows CSRF.

Fix: after 2018-09-11
Fix from $1,950 2019-01-22
Insight HIGH 8.8
CVE-2019-6510

An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSRF.

Fix: after 2018-09-11
Fix from $1,950 2019-01-22
Nedi HIGH 8.8
CVE-2018-20728

A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php.

Fix: after 1.7c
Fix from $1,950 2019-01-17
Zenbership HIGH 8.8
CVE-2016-10738

Zenbership v107 has CSRF via admin/cp-functions/event-add.php.

No fix yet
Fix from $1,950 2019-01-16
Easycms HIGH 8.8
CVE-2019-6294

An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI.

No fix yet
Fix from $1,950 2019-01-15
Hucart HIGH 8.8
CVE-2019-6249

An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_in…

No fix yet
Fix from $1,950 2019-01-13
Usualtoolcms HIGH 8.8
CVE-2019-6244

An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL statements, and consequently exec…

No fix yet
Fix from $1,950 2019-01-12
Junit MEDIUM 6.5
CVE-2018-1000411

A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of …

Fix: after 1.25
Fix from $1,600 2019-01-09
Config File Provider HIGH 8.1
CVE-2018-1000414

A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigF…

Fix: after 3.1
Fix from $1,950 2019-01-09
Email Extension Template HIGH 8.1
CVE-2018-1000417

A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that …

Fix: after 1.0
Fix from $1,950 2019-01-09
Temmoku HIGH 8.8
CVE-2018-20613

TEMMOKU T1.09 Beta allows admin/user/add CSRF.

No fix yet
Fix from $1,950 2018-12-30
Ucms HIGH 8.8
CVE-2018-20598

UCMS 1.4.7 has ?do=user_addpost CSRF.

No fix yet
Fix from $1,950 2018-12-30
Lei Feng Tv Cms HIGH 8.8
CVE-2018-20603

Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF.

No fix yet
Fix from $1,950 2018-12-30
Universal Website Asthis HIGH 8.8
CVE-2018-20612

UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.

No fix yet
Fix from $1,950 2018-12-30
Hsweb HIGH 8.8
CVE-2018-20595

A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the requ…

Patch available
Fix from $1,950 2018-12-30
Microstrategy HIGH 8.8
CVE-2018-18696

main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has…

Fix: after 10.4.0026.0049
Fix from $1,950 2018-12-28
Arv7519rw22 Livebox 2.1 Firmware MEDIUM 5.4
CVE-2018-20576

Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an …

No fix yet
Fix from $1,600 2018-12-28
Arv7519rw22 Livebox 2.1 Firmware CRITICAL 9.1
CVE-2018-20577

Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi…

No fix yet
Fix from $2,300 2018-12-28
Engelsystem HIGH 8.8
CVE-2018-19182

Engelsystem before commit hash 2e28336 allows CSRF.

Fix: 3.0.0+
Fix from $1,950 2018-12-26