Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Dedecms HIGH 8.8
CVE-2018-7700EPSS 75%

DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp…

No fix yet
Fix from $1,950 2018-03-27
Mailer HIGH 8.0
CVE-2018-8718EPSS 7%

Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized ma…

Fix: after 1.20
Fix from $1,950 2018-03-27
Debian Linux HIGH 8.8
CVE-2018-8764

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for …

Fix: 6.3+
Fix from $1,950 2018-03-27
Emc Isilon Onefs HIGH 8.8
CVE-2018-1213

Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.…

Fix: after 8.1.0.1
Fix from $1,950 2018-03-26
Wampserver HIGH 8.8
CVE-2018-8817

Wampserver before 3.1.3 has CSRF in add_vhost.php.

Fix: 3.1.3+
Fix from $1,950 2018-03-25
Open Audit HIGH 8.8
CVE-2018-8979

Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.

No fix yet
Fix from $1,950 2018-03-25
Cwcms HIGH 8.8
CVE-2018-8972

Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28 has CSRF in the functionality for updating the site configuration, which allows remote att…

Fix: 2017-07-28+
Fix from $1,950 2018-03-24
I\, Librarian HIGH 8.8
CVE-2018-1000137

I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can result in the password of the a…

Fix: after 4.8
Fix from $1,950 2018-03-23
G Cam\/efd 2250 Firmware HIGH 8.8
CVE-2018-7524

A cross-site request forgery vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP…

Mitigation only
Fix from $1,950 2018-03-22
Edgeos HIGH 8.0
CVE-2017-0933

Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attacker with access to an operato…

Fix: after 1.9.1
Fix from $1,950 2018-03-22
Spring Batch Admin HIGH 8.8
CVE-2018-1230

Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticated user could craft a malicio…

Mitigation only
Fix from $1,950 2018-03-21
Open Web Analytics HIGH 8.8
CVE-2014-1457

Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protectio…

Fix: 1.5.6+
Fix from $1,950 2018-03-20
Opencms HIGH 8.8
CVE-2018-8811

Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack …

No fix yet
Fix from $1,950 2018-03-20
Subscribe To Comments Reloaded HIGH 8.8
CVE-2014-2274

Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to h…

Fix: after 140204
Fix from $1,950 2018-03-19
Disable Comments Project HIGH 8.8
CVE-2014-2550

Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authe…

Fix: 1.0.4+
Fix from $1,950 2018-03-19
Wp Html Sitemap MEDIUM 6.5
CVE-2014-2675

Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress allows remote attackers to hijac…

No fix yet
Fix from $1,600 2018-03-19
Piwigo MEDIUM 6.5
CVE-2014-4613

Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attackers to hijack the authenticati…

Fix: 2.6.2+
Fix from $1,600 2018-03-16
Email Encryption Gateway HIGH 8.8
CVE-2018-6224

A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit au…

Patch available
Fix from $1,950 2018-03-15
Joyplus Cms HIGH 8.8
CVE-2018-8717

joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.

No fix yet
Fix from $1,950 2018-03-15
Securmail MEDIUM 6.5
CVE-2018-7701

Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authentication…

Fix: 9.2.501+
Fix from $1,600 2018-03-15
Access Manager HIGH 8.8
CVE-2018-7677

A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.

Mitigation only
Fix from $1,950 2018-03-14
Pym.js HIGH 8.8
CVE-2018-1000086

NPR Visuals Team Pym.js version versions 0.4.2 up to 1.3.1 contains a Cross ite Request Forgery (CSRF) vulnerability in Pym.js _onNavigateToMessage f…

Fix: after 1.3.1
Fix from $1,950 2018-03-13
Cms Made Simple HIGH 8.8
CVE-2018-1000092

CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can…

No fix yet
Fix from $1,950 2018-03-13
Cryptonote HIGH 8.8
CVE-2018-1000093

CryptoNote version version 0.8.9 and possibly later contain a local RPC server which does not require authentication, as a result the walletd and the…

Fix: after 0.8.9
Fix from $1,950 2018-03-13
Ajenti HIGH 8.8
CVE-2018-1000082

Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the serv…

No fix yet
Fix from $1,950 2018-03-13
Financial Transaction Manager HIGH 8.0
CVE-2016-0272

Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x be…

Fix: after 3.0.0.12
Fix from $1,950 2018-03-09
Monitoring HIGH 8.8
CVE-2018-1442

IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.4) is vulnerable to cross-site request forgery which coul…

Mitigation only
Fix from $1,950 2018-03-08
Media Streaming Add On HIGH 8.8
CVE-2017-7641

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.

Fix: after 430.1.2.0
Fix from $1,950 2018-03-08
Data Center Network Manager HIGH 8.8
CVE-2018-0210

A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct…

Mitigation only
Fix from $1,950 2018-03-08
Identity Services Engine MEDIUM 6.3
CVE-2018-0215

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond…

Mitigation only
Fix from $1,600 2018-03-08