Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Fledrcms HIGH 8.8
CVE-2018-15846

An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator's password via index.php?p=do…

Fix: after 2014-02-03
Fix from $1,950 2018-08-25
Portfoliocms HIGH 8.8
CVE-2018-15848

An issue was discovered in portfolioCMS 1.0.5. There is CSRF to create new pages via admin/portfolio.php?newpage=true.

Mitigation only
Fix from $1,950 2018-08-25
Moderator Log Notes MEDIUM 6.5
CVE-2018-11502

An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. A…

No fix yet
Fix from $1,600 2018-08-24
Ansible Tower HIGH 8.8
CVE-2018-10884

Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could expl…

Fix: after 3.2.6
Fix from $1,950 2018-08-22
Simple Cms HIGH 8.8
CVE-2018-15564

An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any page via admin/?delpage=8.

Fix: after 2014-03-11
Fix from $1,950 2018-08-20
Simple Cms HIGH 8.8
CVE-2018-15565

An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a page. This can …

Fix: after 2014-03-11
Fix from $1,950 2018-08-20
Tp5cms HIGH 8.8
CVE-2018-15568

tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html.

Fix: after 2017-05-25
Fix from $1,950 2018-08-20
My Little Forum MEDIUM 6.5
CVE-2018-15569

my little forum 2.4.12 allows CSRF for deletion of users.

Mitigation only
Fix from $1,600 2018-08-20
Pimcore HIGH 8.8
CVE-2018-14057

Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-toke…

Fix: 5.3.0+
Fix from $1,950 2018-08-17
Api Connect CRITICAL 9.9
CVE-2018-1712

IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input p…

Fix: after 5.0.8.3
Fix from $2,300 2018-08-16
Tivoli Application Dependency Discovery Manager HIGH 8.8
CVE-2018-1455

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execut…

Mitigation only
Fix from $1,950 2018-08-15
Questions For Confluence MEDIUM 6.5
CVE-2018-13393

The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated t…

Fix: 2.6.6+
Fix from $1,600 2018-08-15
Questions For Confluence MEDIUM 6.5
CVE-2018-13394

The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed …

Fix: 2.6.6+
Fix from $1,600 2018-08-15
Businessobjects Business Intelligence HIGH 8.8
CVE-2018-2442

In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session …

Mitigation only
Fix from $1,950 2018-08-14
3par Service Provider HIGH 8.8
CVE-2018-7097

A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to …

Mitigation only
Fix from $1,950 2018-08-14
Nwl 25 Firmware HIGH 8.8
CVE-2018-14783

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forgery condition can occur, allo…

Fix: after 2.0.29.11
Fix from $1,950 2018-08-10
Auditor Website Project HIGH 8.8
CVE-2018-15186

PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php.

No fix yet
Fix from $1,950 2018-08-10
Advanced Real Estate Script HIGH 8.0
CVE-2018-15187

PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.

No fix yet
Fix from $1,950 2018-08-10
Ecommerce MEDIUM 6.3
CVE-2018-15202

An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/template/includes/crudTreatment.p…

No fix yet
Fix from $1,600 2018-08-08
Ignitedcms MEDIUM 6.5
CVE-2018-15203

An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages.

Fix: after 2017-02-19
Fix from $1,600 2018-08-08
Onethink HIGH 8.8
CVE-2018-15197

An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow administrator priv…

No fix yet
Fix from $1,950 2018-08-08
Onethink HIGH 8.8
CVE-2018-15198

An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a user.

No fix yet
Fix from $1,950 2018-08-08
Gogs HIGH 8.8
CVE-2018-15193

A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.

No fix yet
Fix from $1,950 2018-08-08
Gxlcms HIGH 8.8
CVE-2018-15177

In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.

Mitigation only
Fix from $1,950 2018-08-08
Csrf Magic HIGH 8.8
CVE-2013-7464

In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to …

Fix: 1.0.4+
Fix from $1,950 2018-08-08
Clearpass HIGH 8.8
CVE-2018-7060

Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate…

Fix: 6.6.9 / 6.7.1+
Fix from $1,950 2018-08-06
Qcms HIGH 8.8
CVE-2018-14978

An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.

No fix yet
Fix from $1,950 2018-08-06
Xiao5ucompany HIGH 8.8
CVE-2018-14960

Xiao5uCompany 1.7 has CSRF via admin/Admin.asp.

No fix yet
Fix from $1,950 2018-08-06
Zzcms HIGH 8.8
CVE-2018-14963

zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI.

No fix yet
Fix from $1,950 2018-08-06
Emlsoft HIGH 8.8
CVE-2018-14965

An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=address&do=add page allows CSRF.

No fix yet
Fix from $1,950 2018-08-06