Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Packaged Contact Center Enterprise MEDIUM 6.1
CVE-2018-0444

A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthenticated, remote attacker to …

Mitigation only
Fix from $1,600 2018-10-05
Packaged Contact Center Enterprise HIGH 8.8
CVE-2018-0445

A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthenticated, remote attacker to …

Mitigation only
Fix from $1,950 2018-10-05
Network Level Service HIGH 8.8
CVE-2018-0446

A vulnerability in the web-based management interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct…

Mitigation only
Fix from $1,950 2018-10-05
Razorcms HIGH 8.8
CVE-2018-17986

rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user.

No fix yet
Fix from $1,950 2018-10-05
F2a70a Firmware HIGH 8.8
CVE-2018-5921

A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions. This vulnerab…

Fix: 2405129_000052 / 2405129_000055+
Fix from $1,950 2018-10-03
H660gw Firmware HIGH 8.8
CVE-2018-17869

DASAN H660GW devices do not implement any CSRF protection mechanism.

Mitigation only
Fix from $1,950 2018-10-01
Tl Wrn841n Firmware HIGH 8.8
CVE-2018-15702

The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to CSRF due to insufficient validation of the referer field.

Mitigation only
Fix from $1,950 2018-10-01
Hisiphp HIGH 8.8
CVE-2018-17826

HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then use that account to execute ar…

No fix yet
Fix from $1,950 2018-10-01
Proget MEDIUM 6.5
CVE-2017-15608

Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.

Fix: 5.0.4+
Fix from $1,600 2018-09-26
E Alert Firmware HIGH 8.8
CVE-2018-8844

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a well-formed…

No fix yet
Fix from $1,950 2018-09-26
Mcms HIGH 8.8
CVE-2018-17366

An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

Mitigation only
Fix from $1,950 2018-09-23
Orchestration Designer HIGH 8.8
CVE-2018-15612

A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administr…

Fix: 7.2.1+
Fix from $1,950 2018-09-21
Arcsight Management Center HIGH 8.8
CVE-2018-6504

A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. …

Fix: 2.81+
Fix from $1,950 2018-09-20
Crucible MEDIUM 6.5
CVE-2018-13398

The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit setti…

Fix: 4.5.4+
Fix from $1,600 2018-09-18
Webcenter Interaction HIGH 8.8
CVE-2018-16952

The Oracle WebCenter Interaction Portal 10.3.3 does not implement protection against Cross-site Request Forgery in its design. The impact is sensitiv…

Mitigation only
Fix from $1,950 2018-09-18
Getsimple Cms HIGH 8.8
CVE-2018-17103

An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. …

No fix yet
Fix from $1,950 2018-09-16
Microweber HIGH 8.8
CVE-2018-17104

An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.

Patch available
Fix from $1,950 2018-09-16
Quickapps Cms HIGH 8.8
CVE-2018-17102

An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me U…

Fix: after 1.1.2
Fix from $1,950 2018-09-16
Unlcms MEDIUM 6.5
CVE-2018-17069

An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay.

No fix yet
Fix from $1,600 2018-09-15
Unlcms MEDIUM 6.5
CVE-2018-17070

An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overl…

No fix yet
Fix from $1,600 2018-09-15
Cms Maelostore HIGH 8.8
CVE-2018-17045

An issue was discovered in CMS MaeloStore V.1.5.0. There is a CSRF vulnerability that can change the administrator password via admin/modul/users/aks…

No fix yet
Fix from $1,950 2018-09-14
Gt Ac5300 Firmware HIGH 8.8
CVE-2018-17023

Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.0.4.384_32738 allows remote attackers to hijack t…

Fix: after 3.0.0.4.384_32738
Fix from $1,950 2018-09-13
Xunfeng HIGH 8.0
CVE-2018-16951

xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to CVE-2018-16832.

No fix yet
Fix from $1,950 2018-09-12
Xunfeng MEDIUM 6.5
CVE-2018-16832

CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can ov…

Patch available
Fix from $1,600 2018-09-11
Monit MEDIUM 6.5
CVE-2016-7067

Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable a…

Fix: 5.20.0+
Fix from $1,600 2018-09-10
Cscms HIGH 8.8
CVE-2018-16732

\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.

Mitigation only
Fix from $1,950 2018-09-08
Wl 330nul Firmware HIGH 8.8
CVE-2018-0647

Cross-site request forgery (CSRF) vulnerability in WL-330NUL Firmware version prior to 3.0.0.46 allows remote attackers to hijack the authentication …

Fix: 3.0.0.46+
Fix from $1,950 2018-09-07
Phpmyfaq HIGH 8.8
CVE-2018-16650

phpMyFAQ before 2.9.11 allows CSRF.

Fix: 2.9.11+
Fix from $1,950 2018-09-07
Koha HIGH 8.8
CVE-2018-1000669

KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerability in…

Fix: after 17.05.05
Fix from $1,950 2018-09-06
Django Crm HIGH 8.8
CVE-2018-16552

MicroPyramid Django-CRM 0.2 allows CSRF for /users/create/, /users/##/edit/, and /accounts/##/delete/ URIs.

No fix yet
Fix from $1,950 2018-09-05