Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Rainmachine Web Application HIGH 8.8
CVE-2018-6907

A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows…

No fix yet
Fix from $1,950 2018-11-01
Z Blogphp HIGH 8.8
CVE-2018-18842

CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code.

No fix yet
Fix from $1,950 2018-10-30
Catfish Cms HIGH 8.8
CVE-2018-18734

A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.

No fix yet
Fix from $1,950 2018-10-29
Catfish Blog HIGH 8.8
CVE-2018-18735

A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.

No fix yet
Fix from $1,950 2018-10-29
Semcms HIGH 8.8
CVE-2018-18742

A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.

No fix yet
Fix from $1,950 2018-10-29
Wuzhicms HIGH 8.8
CVE-2018-18712

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f…

No fix yet
Fix from $1,950 2018-10-29
Wuzhicms HIGH 8.8
CVE-2018-18711

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=p…

No fix yet
Fix from $1,950 2018-10-29
9px Ups Firmware HIGH 8.8
CVE-2018-9281

An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionalit…

Mitigation only
Fix from $1,950 2018-10-24
Zenario HIGH 8.8
CVE-2018-18420

Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.p…

No fix yet
Fix from $1,950 2018-10-19
Koha HIGH 8.0
CVE-2015-4630

Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x be…

Fix: 3.14.16 / 3.16.12+
Fix from $1,950 2018-10-18
Ubuntu Linux HIGH 8.8
CVE-2018-12370

In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded…

Fix: 61.0+
Fix from $1,950 2018-10-18
Enterprise Linux Desktop HIGH 8.8
CVE-2018-12364

NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect t…

Mitigation only
Fix from $1,950 2018-10-18
Prime Collaboration Assurance MEDIUM 6.5
CVE-2018-15438

A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to condu…

Mitigation only
Fix from $1,600 2018-10-17
Enterprise Network Virtualization Software HIGH 8.8
CVE-2018-15402

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to conduct cross-site request…

Mitigation only
Fix from $1,950 2018-10-17
Jtbc Php HIGH 8.8
CVE-2018-18436

JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.

No fix yet
Fix from $1,950 2018-10-17
Usualtoolcms HIGH 8.8
CVE-2018-18422

UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI.

No fix yet
Fix from $1,950 2018-10-17
Destoon B2b HIGH 8.8
CVE-2018-18432

An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request.

No fix yet
Fix from $1,950 2018-10-17
Cockpit HIGH 8.8
CVE-2018-15539

Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.

Mitigation only
Fix from $1,950 2018-10-15
Emlog HIGH 8.8
CVE-2018-18316

emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.

No fix yet
Fix from $1,950 2018-10-15
Dscms HIGH 8.8
CVE-2018-18317

DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI.

No fix yet
Fix from $1,950 2018-10-15
Youke 365 HIGH 8.8
CVE-2018-18215

In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.

No fix yet
Fix from $1,950 2018-10-11
Nplug Firmware HIGH 8.8
CVE-2018-12456

Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as …

No fix yet
Fix from $1,950 2018-10-10
Simatic S7 1200 V4 Firmware HIGH 7.3
CVE-2018-13800

A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface could allow a Cross-Site Reque…

Fix: 4.2.3+
Fix from $1,950 2018-10-10
Qibosoft HIGH 8.8
CVE-2018-18201

qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.

No fix yet
Fix from $1,950 2018-10-09
Joomla\! HIGH 8.8
CVE-2018-17858

An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.

Fix: 3.8.13+
Fix from $1,950 2018-10-09
Finecms HIGH 8.8
CVE-2018-18191

Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote attackers to change the admin…

No fix yet
Fix from $1,950 2018-10-09
Fiori MEDIUM 6.5
CVE-2018-2474

SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended req…

Mitigation only
Fix from $1,600 2018-10-09
Hosted Collaboration Mediation Fulfillment MEDIUM 6.5
CVE-2018-15401

A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,600 2018-10-05
Tetration Analytics HIGH 8.8
CVE-2018-0451

A vulnerability in the web-based management interface of Cisco Tetration Analytics could allow an authenticated, remote attacker to conduct a cross-s…

Mitigation only
Fix from $1,950 2018-10-05
Meeting Server HIGH 8.8
CVE-2018-0439

A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site…

Mitigation only
Fix from $1,950 2018-10-05