Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Jirafeau HIGH 8.8
CVE-2018-11349

The administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_by_name, search_by_hash, and …

Fix: 3.4.1+
Fix from $1,950 2018-07-07
Gleez Cms HIGH 8.8
CVE-2018-13340

Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request.

No fix yet
Fix from $1,950 2018-07-05
Beescms HIGH 8.8
CVE-2018-12739

In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.

No fix yet
Fix from $1,950 2018-07-05
Damicms HIGH 8.8
CVE-2018-13031

DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.

No fix yet
Fix from $1,950 2018-07-05
Rails Admin HIGH 8.8
CVE-2016-10522

rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a re…

Fix: 1.1.1+
Fix from $1,950 2018-07-05
Powermedia Xms HIGH 8.8
CVE-2018-11636

Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to execu…

Fix: after 3.5
Fix from $1,950 2018-07-03
Opencart HIGH 8.8
CVE-2018-13067

/upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's …

Fix: after 3.0.2.0
Fix from $1,950 2018-07-02
N150 Firmware HIGH 8.8
CVE-2018-12529

An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user…

No fix yet
Fix from $1,950 2018-07-02
Tl Wr841n Firmware HIGH 8.8
CVE-2018-12574

CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices.

Mitigation only
Fix from $1,950 2018-07-02
Opensid HIGH 8.8
CVE-2018-13040

OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerability can add an account (at the admin level) via the index.php/man_user/insert URI.

No fix yet
Fix from $1,950 2018-07-01
Shieldlink Sl175ehq Firmware HIGH 8.8
CVE-2018-13032

ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI.

No fix yet
Fix from $1,950 2018-07-01
Wstmall HIGH 8.8
CVE-2018-13010

WSTMall v1.9.1_170316 has CSRF via the index.php?m=Admin&c=Users&a=edit URI to add a user account.

No fix yet
Fix from $1,950 2018-06-29
Easycms MEDIUM 6.5
CVE-2018-12971

EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.

No fix yet
Fix from $1,600 2018-06-29
Scalance M875 Firmware HIGH 8.8
CVE-2018-11447

A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a Cross-Site Request Forgery (CSRF…

Mitigation only
Fix from $1,950 2018-06-26
Tooltipy MEDIUM 6.5
CVE-2018-1000505

Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybod…

No fix yet
Fix from $1,600 2018-06-26
Metronet Tag Manager HIGH 8.8
CVE-2018-1000506

Metronet Tag Manager version 1.2.7 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page /wp-admin/options-general.php?page=metr…

No fix yet
Fix from $1,950 2018-06-26
Wp User Groups MEDIUM 6.5
CVE-2018-1000507

WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify u…

No fix yet
Fix from $1,600 2018-06-26
Lfcms HIGH 8.8
CVE-2018-12603

Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users…

No fix yet
Fix from $1,950 2018-06-25
Lfcms HIGH 8.8
CVE-2018-12602

A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.

No fix yet
Fix from $1,950 2018-06-25
Slims Akasia HIGH 8.8
CVE-2018-12659

SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter.

No fix yet
Fix from $1,950 2018-06-22
Unified Communications Manager Im And Presence Service HIGH 8.8
CVE-2018-0363

A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could allow an un…

Mitigation only
Fix from $1,950 2018-06-21
Unified Communications Domain Manager HIGH 8.8
CVE-2018-0364

A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker …

Mitigation only
Fix from $1,950 2018-06-21
Secure Firewall Management Center HIGH 8.8
CVE-2018-0365

A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct…

Mitigation only
Fix from $1,950 2018-06-21
Encryption Gateway HIGH 8.8
CVE-2018-6563

Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack t…

Fix: after 6.0.0
Fix from $1,950 2018-06-20
Akcms HIGH 8.8
CVE-2018-12582

An issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&job=newaccount URI.

No fix yet
Fix from $1,950 2018-06-19
Akcms MEDIUM 6.5
CVE-2018-12583

An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.

No fix yet
Fix from $1,600 2018-06-19
Universal Cmbd Browser HIGH 8.8
CVE-2018-6496

Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which coul…

Fix: after 4.15.1
Fix from $1,950 2018-06-16
Cms Server HIGH 8.8
CVE-2018-6497

Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10…

Fix: after 11.0
Fix from $1,950 2018-06-16
Maccms HIGH 8.8
CVE-2018-12114

Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.

No fix yet
Fix from $1,950 2018-06-14
Knowage HIGH 8.8
CVE-2018-12354

Knowage (formerly SpagoBI) 6.1.1 allows CSRF via every form, as demonstrated by a /knowage/restful-services/2.0/analyticalDrivers/ POST request.

Mitigation only
Fix from $1,950 2018-06-13