Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Douphp HIGH 8.8
CVE-2018-20419

DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.

No fix yet
Fix from $1,950 2018-12-24
Unified Endpoint Manager MEDIUM 6.5
CVE-2018-8892

A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to…

Fix: 12.9.1+
Fix from $1,600 2018-12-20
Ubuntu Linux HIGH 8.8
CVE-2018-1000858

GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Infor…

Fix: after 2.2.11
Fix from $1,950 2018-12-20
Luigi HIGH 8.8
CVE-2018-1000843

Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contains a Cross…

Fix: 2.8.0+
Fix from $1,950 2018-12-20
Freshdns HIGH 8.8
CVE-2018-1000846

FreshDNS version 1.0.3 and earlier contains a Cross ite Request Forgery (CSRF) vulnerability in All (authenticated) API calls in index.php / class.ma…

Fix: after 1.0.3
Fix from $1,950 2018-12-20
Datapower Gateway HIGH 8.8
CVE-2018-1661

IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Fix: after 7.6.0.9
Fix from $1,950 2018-12-20
Subsonic HIGH 8.0
CVE-2018-20228

Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.

No fix yet
Fix from $1,950 2018-12-19
Two Factor Authentication HIGH 8.8
CVE-2018-20231

Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the …

Fix: 1.3.13+
Fix from $1,950 2018-12-19
Integria Ims MEDIUM 6.5
CVE-2018-19829

Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is kn…

No fix yet
Fix from $1,600 2018-12-18
Php Server Monitor MEDIUM 6.5
CVE-2018-18921

PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action.

Fix: 3.3.2+
Fix from $1,600 2018-12-18
Fuel Cms HIGH 8.8
CVE-2018-20188

FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.

No fix yet
Fix from $1,950 2018-12-17
Icinga Web 2 MEDIUM 6.5
CVE-2018-18246

Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/m…

Fix: 2.6.2+
Fix from $1,600 2018-12-17
Websphere Application Server HIGH 8.8
CVE-2018-1926

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of u…

Fix: after 9.0.0.9
Fix from $1,950 2018-12-12
phpMyAdmin HIGH 8.8
CVE-2018-19969

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is …

Fix: 4.8.4+
Fix from $1,950 2018-12-11
Yzmcms HIGH 8.8
CVE-2018-20015

YzmCMS v5.2 has admin/role/add.html CSRF.

No fix yet
Fix from $1,950 2018-12-10
Sales \& Company Management System HIGH 8.8
CVE-2018-19923

An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF.

Fix: after 2018-06-06
Fix from $1,950 2018-12-06
Freeswitch HIGH 7.5
CVE-2018-19911

FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or …

Fix: after 1.8.2
Fix from $1,950 2018-12-06
Minikube HIGH 8.8
CVE-2018-1002103

In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is…

Fix: after 0.29.0
Fix from $1,950 2018-12-05
Pluck HIGH 8.8
CVE-2018-16634

Pluck v4.7.7 allows CSRF via admin.php?action=settings.

No fix yet
Fix from $1,950 2018-12-04
Modicom M340 Firmware HIGH 8.8
CVE-2018-7831

An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340…

No fix yet
Fix from $1,950 2018-11-30
Storediq HIGH 8.8
CVE-2018-1927

IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Fix: 7.6.0.17+
Fix from $1,950 2018-11-30
Showdoc MEDIUM 6.5
CVE-2018-19621

server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.

No fix yet
Fix from $1,600 2018-11-28
Nsa325 V2 Firmware HIGH 8.8
CVE-2018-14892

Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changi…

No fix yet
Fix from $1,950 2018-11-27
Moodle HIGH 8.8
CVE-2018-16854

A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token t…

Fix: 3.1.15 / 3.3.9+
Fix from $1,950 2018-11-26
Teleport HIGH 8.8
CVE-2018-19555

tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password.

No fix yet
Fix from $1,950 2018-11-26
Bagecms HIGH 8.8
CVE-2018-19560

BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.

No fix yet
Fix from $1,950 2018-11-26
Sikcms HIGH 8.8
CVE-2018-19561

sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account.

No fix yet
Fix from $1,950 2018-11-26
Jeecms MEDIUM 6.5
CVE-2018-19544

JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news.

No fix yet
Fix from $1,600 2018-11-26
Jeecms HIGH 8.8
CVE-2018-19545

JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.

No fix yet
Fix from $1,950 2018-11-26
Jtbc Php HIGH 8.8
CVE-2018-19546

JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter.

No fix yet
Fix from $1,950 2018-11-26