Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Symfony HIGH 8.8
CVE-2018-11406

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and …

Fix: 2.7.48 / 2.8.41+
Fix from $1,950 2018-06-13
Firefox HIGH 8.8
CVE-2017-5394

A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript even…

Fix: 51.0+
Fix from $1,950 2018-06-11
Open Build Service HIGH 8.8
CVE-2014-0594

In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without …

Fix: 2.4.6+
Fix from $1,950 2018-06-08
Photo Station HIGH 8.8
CVE-2018-8925

Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attac…

Fix: 6.3-2975 / 6.8.5-3471+
Fix from $1,950 2018-06-08
Robotic Process Automation With Automation Anywhere HIGH 8.8
CVE-2018-1514

IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute mal…

Patch available
Fix from $1,950 2018-06-07
Ip Gateway Firmware HIGH 8.8
CVE-2017-7906

In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow…

Fix: after 3.39
Fix from $1,950 2018-06-06
Nas Proxy Server HIGH 8.8
CVE-2017-7635

QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.

Fix: 1.3.0+
Fix from $1,950 2018-06-05
Infosphere Information Server MEDIUM 6.1
CVE-2018-1432

IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker t…

Mitigation only
Fix from $1,600 2018-06-05
Cmseasy HIGH 8.8
CVE-2018-11679

An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archiv…

No fix yet
Fix from $1,950 2018-06-02
Cmseasy MEDIUM 6.5
CVE-2018-11680

An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be …

No fix yet
Fix from $1,600 2018-06-02
Searchblox HIGH 8.8
CVE-2018-11538EPSS 13%

servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token B…

No fix yet
Fix from $1,950 2018-06-01
Greencms HIGH 8.8
CVE-2018-11670

An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content para…

No fix yet
Fix from $1,950 2018-06-01
Greencms HIGH 8.8
CVE-2018-11671

An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserha…

No fix yet
Fix from $1,950 2018-06-01
Add Social Share Messenger Buttons Whatsapp And Viber MEDIUM 6.5
CVE-2018-11632

An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tr…

No fix yet
Fix from $1,600 2018-05-31
Woo Checkout For Digital Goods MEDIUM 6.5
CVE-2018-11633

An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can be tricked into visiting a cra…

No fix yet
Fix from $1,600 2018-05-31
Droppy HIGH 8.8
CVE-2016-10529

Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page th…

Fix: 3.5.0+
Fix from $1,950 2018-05-31
Zimbra Collaboration Suite HIGH 8.8
CVE-2015-7610

Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 …

Fix: after 8.8.8
Fix from $1,950 2018-05-30
Cscms HIGH 8.8
CVE-2018-11527

An issue was discovered in CScms v4.1. A Cross-site request forgery (CSRF) vulnerability in plugins/sys/admin/Sys.php allows remote attackers to chan…

No fix yet
Fix from $1,950 2018-05-29
Publiccms HIGH 8.8
CVE-2018-11500

An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUse…

No fix yet
Fix from $1,950 2018-05-26
Website Seller Script HIGH 8.8
CVE-2018-11501

PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.

No fix yet
Fix from $1,950 2018-05-26
Wuzhicms HIGH 8.8
CVE-2018-11493

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.

No fix yet
Fix from $1,950 2018-05-26
Pi Coresight HIGH 8.8
CVE-2017-9641

PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrad…

Fix: after 2016-r2
Fix from $1,950 2018-05-25
Easyservice Billing HIGH 8.8
CVE-2018-11442

A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding…

No fix yet
Fix from $1,950 2018-05-25
Easyservice Billing HIGH 8.8
CVE-2018-11445

A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with…

No fix yet
Fix from $1,950 2018-05-25
Kliqqi Cms HIGH 8.8
CVE-2018-11405

Kliqqi 2.0.2 has CSRF in admin/admin_users.php.

No fix yet
Fix from $1,950 2018-05-24
Skycaiji HIGH 8.8
CVE-2018-11371

SkyCaiji 1.2 allows CSRF to add an Administrator user.

No fix yet
Fix from $1,950 2018-05-22
Admin Notes MEDIUM 6.5
CVE-2018-11092

An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?emp…

Patch available
Fix from $1,600 2018-05-21
Horse Market Sell \& Rent Portal MEDIUM 6.5
CVE-2018-11096

Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the target's account information re…

No fix yet
Fix from $1,600 2018-05-21
Storwize V7000 Firmware HIGH 8.8
CVE-2018-1434

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,950 2018-05-17
Iot Field Network Director HIGH 8.8
CVE-2018-0270

A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker t…

No fix yet
Fix from $1,950 2018-05-17