Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Jenkins MEDIUM 5.4
CVE-2017-2613

jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restar…

Fix: 2.32.2 / 2.44+
Fix from $1,600 2018-05-15
Doorgets HIGH 8.8
CVE-2018-11126

dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account.

No fix yet
Fix from $1,950 2018-05-15
E107 MEDIUM 6.5
CVE-2018-11127

e107 2.1.7 has CSRF resulting in arbitrary user deletion.

Mitigation only
Fix from $1,600 2018-05-15
Edr 810 Firmware HIGH 8.8
CVE-2017-12126

An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially craft…

No fix yet
Fix from $1,950 2018-05-14
Pbootcms HIGH 8.8
CVE-2018-11018

An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows…

No fix yet
Fix from $1,950 2018-05-13
Yxcms MEDIUM 6.5
CVE-2018-11003

An issue was discovered in YXcms 1.4.7. Cross-site request forgery (CSRF) vulnerability in protected/apps/admin/controller/adminController.php allows…

No fix yet
Fix from $1,600 2018-05-12
Sdcms HIGH 8.8
CVE-2018-11004

An issue was discovered in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/admincontroller.php allows remot…

No fix yet
Fix from $1,950 2018-05-12
Fastgate Firmware HIGH 8.8
CVE-2018-6023

Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc.

No fix yet
Fix from $1,950 2018-05-11
Easy Hosting Control Panel HIGH 8.8
CVE-2018-6458EPSS 10%

Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF …

No fix yet
Fix from $1,950 2018-05-11
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2018-10803

Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 1231…

Fix: 12.3.125+
Fix from $1,600 2018-05-10
Dir 868l Firmware HIGH 8.8
CVE-2018-10957

CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affecte…

No fix yet
Fix from $1,950 2018-05-10
Frogcms MEDIUM 5.4
CVE-2018-10806

An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/…

No fix yet
Fix from $1,600 2018-05-08
Yellow MEDIUM 6.5
CVE-2018-10758

The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.

No fix yet
Fix from $1,600 2018-05-05
Eap Controller HIGH 8.8
CVE-2018-10166

The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens i…

No fix yet
Fix from $1,950 2018-05-03
Manageiq Enterprise Virtualization Manager HIGH 8.8
CVE-2013-0185

Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authenticat…

No fix yet
Fix from $1,950 2018-05-01
Nagios Xi MEDIUM 5.4
CVE-2018-10554

An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm pa…

No fix yet
Fix from $1,600 2018-04-30
Baijiacms HIGH 8.8
CVE-2018-10503

An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105. CSRF allows adding an administrator account via op=edituser, changing the admin…

No fix yet
Fix from $1,950 2018-04-27
Bigfix Platform HIGH 8.8
CVE-2018-1479

IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actio…

Fix: after 9.5.8
Fix from $1,950 2018-04-27
Wuzhicms HIGH 8.8
CVE-2018-10312

index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.

No fix yet
Fix from $1,950 2018-04-24
User Profile \& Membership HIGH 8.8
CVE-2018-10233

The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a …

Fix: 2.0.7+
Fix from $1,950 2018-04-23
Chemcms HIGH 8.8
CVE-2018-10295

ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account.

No fix yet
Fix from $1,950 2018-04-22
Hongcms HIGH 8.8
CVE-2018-10265

An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.

Mitigation only
Fix from $1,950 2018-04-22
Beescms HIGH 8.8
CVE-2018-10266

BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI.

Mitigation only
Fix from $1,950 2018-04-22
Wtcms HIGH 8.8
CVE-2018-10267

WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.

No fix yet
Fix from $1,950 2018-04-22
Baijiacms HIGH 8.8
CVE-2018-10249

baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account.

No fix yet
Fix from $1,950 2018-04-20
Wuzhicms MEDIUM 6.5
CVE-2018-10248

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_del…

No fix yet
Fix from $1,600 2018-04-20
iOS HIGH 8.8
CVE-2018-0255

A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct …

Mitigation only
Fix from $1,950 2018-04-19
Mate Collector HIGH 8.8
CVE-2018-0259

A vulnerability in the web-based management interface of Cisco MATE Collector could allow an unauthenticated, remote attacker to conduct a cross-site…

Mitigation only
Fix from $1,950 2018-04-19
phpMyAdmin HIGH 8.8
CVE-2018-10188

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations…

No fix yet
Fix from $1,950 2018-04-19
Icms HIGH 8.8
CVE-2018-10222

An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&fr…

No fix yet
Fix from $1,950 2018-04-19