Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Greencms MEDIUM 6.5
CVE-2018-19376

An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=d…

No fix yet
Fix from $1,600 2018-11-20
Webpanel HIGH 8.8
CVE-2018-18772

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arb…

Fix: after 0.9.8.740
Fix from $1,950 2018-11-20
Webpanel HIGH 8.8
CVE-2018-18773

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root…

Fix: after 0.9.8.740
Fix from $1,950 2018-11-20
Monorail MEDIUM 5.3
CVE-2018-19335

Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of d…

Fix: 2018-06-07+
Fix from $1,600 2018-11-20
Monorail MEDIUM 5.3
CVE-2018-19334

Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of d…

Fix: 2018-05-04+
Fix from $1,600 2018-11-20
Monorail MEDIUM 5.3
CVE-2018-10099

Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of d…

Fix: 2018-04-04+
Fix from $1,600 2018-11-20
Jtbc Php HIGH 8.8
CVE-2018-19327

An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.

No fix yet
Fix from $1,950 2018-11-17
S Cms HIGH 8.8
CVE-2018-19332

An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.

No fix yet
Fix from $1,950 2018-11-17
Srcms HIGH 8.8
CVE-2018-19318

SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.

No fix yet
Fix from $1,950 2018-11-16
Srcms MEDIUM 6.5
CVE-2018-19319

SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.

No fix yet
Fix from $1,600 2018-11-16
Rhinos MEDIUM 6.5
CVE-2018-18760

RhinOS 3.0 build 1190 allows CSRF.

No fix yet
Fix from $1,600 2018-11-16
School Event Management System HIGH 8.8
CVE-2018-18794

School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.

No fix yet
Fix from $1,950 2018-11-16
School Attendance Monitoring System HIGH 8.8
CVE-2018-18797

School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.

No fix yet
Fix from $1,950 2018-11-16
School Attendance Monitoring System HIGH 8.8
CVE-2018-18799

School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.

No fix yet
Fix from $1,950 2018-11-16
Dilicms MEDIUM 6.5
CVE-2018-19291

An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/in…

No fix yet
Fix from $1,600 2018-11-15
Datasynapse Gridserver Manager HIGH 8.8
CVE-2018-12416

The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager contain vulnerabilities which …

Fix: after 5.2.0
Fix from $1,950 2018-11-13
Laobancms HIGH 8.8
CVE-2018-19225

An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF.

No fix yet
Fix from $1,950 2018-11-12
Xiaocms HIGH 8.8
CVE-2018-19192

An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content]…

No fix yet
Fix from $1,950 2018-11-12
Clippercms HIGH 8.8
CVE-2018-19135

ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions f…

No fix yet
Fix from $1,950 2018-11-11
Zywall Usg 100 Firmware HIGH 8.8
CVE-2017-17550

ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This…

No fix yet
Fix from $1,950 2018-11-10
Wstmart HIGH 8.8
CVE-2018-19138

WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.

No fix yet
Fix from $1,950 2018-11-09
Energy Management Suite Software HIGH 8.0
CVE-2018-15445

A vulnerability in the web-based management interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to cond…

No fix yet
Fix from $1,950 2018-11-08
Bagecms HIGH 8.8
CVE-2018-19104

In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.

No fix yet
Fix from $1,950 2018-11-08
Activespaces HIGH 8.8
CVE-2018-12411

The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and …

Mitigation only
Fix from $1,950 2018-11-06
Ftl HIGH 8.8
CVE-2018-12412

The realm server (tibrealmserver) component of TIBCO Software Inc. TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Ente…

Fix: 5.4.0+
Fix from $1,950 2018-11-06
Messaging Apache Kafka Distribution Schema Repository HIGH 8.8
CVE-2018-12413

The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Commun…

Mitigation only
Fix from $1,950 2018-11-06
Rendezvous HIGH 8.8
CVE-2018-12414

The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), and Rend…

Fix: after 8.4.5
Fix from $1,950 2018-11-06
Enterprise Message Service HIGH 8.8
CVE-2018-12415

The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Com…

Fix: after 8.4.0
Fix from $1,950 2018-11-06
Popojicms CRITICAL 9.8
CVE-2018-18934

An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the …

No fix yet
Fix from $2,300 2018-11-05
Popojicms HIGH 8.8
CVE-2018-18935

An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1…

No fix yet
Fix from $1,950 2018-11-05