Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Identity Services Engine MEDIUM 5.4
CVE-2018-0216

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond…

Mitigation only
Fix from $1,600 2018-03-08
Qdx 6000 Firmware HIGH 8.8
CVE-2018-7565

CSRF exists on Polycom QDX 6000 devices.

No fix yet
Fix from $1,950 2018-03-07
Razor HIGH 8.8
CVE-2018-7746

An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/channel/modifychannel. For example…

No fix yet
Fix from $1,950 2018-03-07
Razor HIGH 8.8
CVE-2018-7720

A cross-site request forgery (CSRF) vulnerability exists in Western Bridge Cobub Razor 0.7.2 via /index.php?/user/createNewUser/, resulting in accoun…

No fix yet
Fix from $1,950 2018-03-07
Vigorap 910c Firmware HIGH 8.8
CVE-2017-11649

Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to hijack…

No fix yet
Fix from $1,950 2018-03-07
Yxtcmf HIGH 8.8
CVE-2018-7733

An issue was discovered in YxtCMF 3.1. RbacController.class.php has CSRF, as demonstrated by modifying an administrator account via index.php/admin/u…

Fix: after 3.1
Fix from $1,950 2018-03-06
Piwigo MEDIUM 5.4
CVE-2018-7724

The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, rel…

No fix yet
Fix from $1,600 2018-03-06
Auth0.js HIGH 8.8
CVE-2018-7307

The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.

Fix: 9.3+
Fix from $1,950 2018-03-06
Tuleap HIGH 8.8
CVE-2018-7634

An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functi…

Patch available
Fix from $1,950 2018-03-01
Hoosk HIGH 8.8
CVE-2018-7590

CSRF exists in Hoosk 1.7.0 via /admin/users/new/add, resulting in account creation.

Mitigation only
Fix from $1,950 2018-03-01
Bigfix Platform HIGH 8.8
CVE-2016-0295

Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the …

Fix: 9.5.2+
Fix from $1,950 2018-02-28
Fs010w Firmware HIGH 8.8
CVE-2018-0520

Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of ad…

Mitigation only
Fix from $1,950 2018-02-23
Data Center Analytics Framework MEDIUM 5.4
CVE-2018-0146

A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site requ…

Mitigation only
Fix from $1,600 2018-02-22
Ucs Director HIGH 8.8
CVE-2018-0148

A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Soft…

Mitigation only
Fix from $1,950 2018-02-22
Hosting HIGH 8.8
CVE-2018-7308

A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any fil…

Fix: after 2018-02-11
Fix from $1,950 2018-02-21
Tririga Application Platform HIGH 8.0
CVE-2016-0348

Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the …

Mitigation only
Fix from $1,950 2018-02-21
Eshop HIGH 7.5
CVE-2017-12415

OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition…

Fix: 4.9.10 / 4.10.5+
Fix from $1,950 2018-02-20
Nat32 MEDIUM 6.1
CVE-2018-6940

A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunctio…

No fix yet
Fix from $1,600 2018-02-20
Nat32 HIGH 8.8
CVE-2018-6941

A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjuncti…

No fix yet
Fix from $1,950 2018-02-20
Helpspot HIGH 8.8
CVE-2017-16756

An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=p…

Fix: after 4.7.1
Fix from $1,950 2018-02-19
Nonecms HIGH 8.8
CVE-2018-7219

application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/ind…

No fix yet
Fix from $1,950 2018-02-19
Bravo Solution HIGH 8.0
CVE-2018-7216

Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated use…

No fix yet
Fix from $1,950 2018-02-18
Frontaccounting HIGH 8.8
CVE-2018-7176

FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Perm…

No fix yet
Fix from $1,950 2018-02-16
Matrix Operating Environment HIGH 8.8
CVE-2017-5781

A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found.

No fix yet
Fix from $1,950 2018-02-15
J9627a Firmware HIGH 8.8
CVE-2017-5796

A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.

Mitigation only
Fix from $1,950 2018-02-15
Version Control Repository Manager HIGH 8.0
CVE-2016-8513

A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior …

Fix: 7.6+
Fix from $1,950 2018-02-15
Powerscada Anywhere HIGH 8.1
CVE-2017-9963

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with…

Mitigation only
Fix from $1,950 2018-02-12
Typesetter HIGH 8.0
CVE-2018-6888

An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: usin…

No fix yet
Fix from $1,950 2018-02-12
Limesurvey HIGH 8.8
CVE-2018-1000053

LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causi…

Patch available
Fix from $1,950 2018-02-09
Manageengine Admanager Plus HIGH 8.8
CVE-2017-17552

/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resultin…

Fix: 6.6+
Fix from $1,950 2018-02-07