Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Emlsoft HIGH 8.8
CVE-2018-14966

An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF.

No fix yet
Fix from $1,950 2018-08-06
Weaselcms HIGH 8.8
CVE-2018-14958

An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php.

No fix yet
Fix from $1,950 2018-08-05
Weaselcms HIGH 8.8
CVE-2018-14959

An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI.

No fix yet
Fix from $1,950 2018-08-05
Banco HIGH 8.8
CVE-2018-14926

Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request.

Mitigation only
Fix from $1,950 2018-08-03
Seacms HIGH 8.8
CVE-2018-14910

SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The…

No fix yet
Fix from $1,950 2018-08-03
Syncthru Web Service HIGH 8.8
CVE-2018-14908

Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupVie…

No fix yet
Fix from $1,950 2018-08-03
Identity Services Engine Software HIGH 8.8
CVE-2018-0413

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond…

No fix yet
Fix from $1,950 2018-08-01
Saltstack HIGH 7.5
CVE-2018-1999027

An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that…

Fix: after 3.1.6
Fix from $1,950 2018-08-01
GitLab HIGH 8.8
CVE-2018-14603

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. CSRF can occur in t…

Fix: 10.8.7 / 11.0.5+
Fix from $1,950 2018-07-27
Bagecms HIGH 8.8
CVE-2018-14582

index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.

No fix yet
Fix from $1,950 2018-07-24
Xyhcms HIGH 8.8
CVE-2018-14583

xyhai.php?s=/Auth/addUser in XYHCMS 3.5 allows CSRF to add a background administrator account.

No fix yet
Fix from $1,950 2018-07-24
Dotcms HIGH 8.8
CVE-2017-3187

The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a …

Fix: after 3.7.1
Fix from $1,950 2018-07-24
Metinfo HIGH 8.8
CVE-2018-14420

MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=…

No fix yet
Fix from $1,950 2018-07-20
Seacms HIGH 8.8
CVE-2018-14421

SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admi…

Mitigation only
Fix from $1,950 2018-07-20
Unified Contact Center Express HIGH 8.8
CVE-2018-0402

Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, …

Mitigation only
Fix from $1,950 2018-07-18
Xiaocms X1 HIGH 8.8
CVE-2018-14331

An issue was discovered in XiaoCms X1 v20140305. There is a CSRF vulnerability to change the administrator account password via admin/index.php?c=ind…

No fix yet
Fix from $1,950 2018-07-17
Srcms HIGH 8.8
CVE-2018-14068

An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Admin&c=manager&a=add.

No fix yet
Fix from $1,950 2018-07-15
Srcms HIGH 8.8
CVE-2018-14069

An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add a user account via admin.php?m=Admin&c=member&a=add.

Mitigation only
Fix from $1,950 2018-07-15
Filecloud HIGH 8.8
CVE-2016-6578

CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability. An attacker can perform act…

Fix: after 13.0.0.32841
Fix from $1,950 2018-07-13
Rp Ac52 Firmware HIGH 8.8
CVE-2016-6557

In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify …

Fix: after 1.0.1.1s
Fix from $1,950 2018-07-13
Artifactory HIGH 8.8
CVE-2018-1000206

JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF a…

Fix: 6.1.0+
Fix from $1,950 2018-07-13
Witycms HIGH 8.8
CVE-2018-14029

CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the ac…

No fix yet
Fix from $1,950 2018-07-13
Super Cms HIGH 8.8
CVE-2018-14014

In waimai Super Cms 20150505, there is a CSRF vulnerability that can add an admin account via admin.php?m=Member&a=adminadd.

No fix yet
Fix from $1,950 2018-07-12
Vert.x HIGH 8.8
CVE-2018-12540

In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter.…

Fix: after 3.5.2
Fix from $1,950 2018-07-12
Qutebrowser HIGH 8.8
CVE-2018-10895

qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious websi…

Fix: 1.4.1+
Fix from $1,950 2018-07-12
Topdesk MEDIUM 6.5
CVE-2018-10232

Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack t…

Fix: 8.05.017+
Fix from $1,600 2018-07-11
Grundig Smart Inter\@ctive Firmware HIGH 8.8
CVE-2018-13989

Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by…

No fix yet
Fix from $1,950 2018-07-11
Flexicapture HIGH 8.8
CVE-2018-13793

Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web Verificati…

Mitigation only
Fix from $1,950 2018-07-09
Seacms HIGH 8.8
CVE-2018-13444

An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_manager.php?action=save&id=2.

No fix yet
Fix from $1,950 2018-07-08
Seacms HIGH 8.8
CVE-2018-13445

An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add a user account via adm1n/admin_manager.php?action=add.

No fix yet
Fix from $1,950 2018-07-08