Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Boot2docker HIGH 8.8
CVE-2014-5280

boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connectio…

Fix: after 1.2.0
Fix from $1,950 2018-02-06
Secure Mail Gateway HIGH 8.8
CVE-2018-6288

Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.

No fix yet
Fix from $1,950 2018-02-06
Flickrrss HIGH 8.8
CVE-2018-6467

The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php.

No fix yet
Fix from $1,950 2018-02-06
Z Blogphp MEDIUM 6.5
CVE-2018-6656

Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories.

Patch available
Fix from $1,600 2018-02-06
Uncurl HIGH 8.8
CVE-2018-6651

In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting …

Fix: 0.07 / 140-3+
Fix from $1,950 2018-02-05
Codestyling Localization HIGH 8.8
CVE-2015-4179

Multiple cross-site request forgery (CSRF) vulnerabilities in the Codestyling Localization plugin 1.99.30 and earlier for Wordpress.

Fix: after 1.99.30
Fix from $1,950 2018-02-05
Subsonic HIGH 8.8
CVE-2017-9414EPSS 15%

Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentic…

No fix yet
Fix from $1,950 2018-02-05
Bamboo HIGH 8.8
CVE-2017-18080

The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site requ…

Fix: 6.3.1+
Fix from $1,950 2018-02-02
Bamboo HIGH 8.8
CVE-2017-18042

The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via …

Fix: 6.3.1+
Fix from $1,950 2018-02-02
Open Atrium HIGH 8.8
CVE-2014-9502

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified sub modules in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal al…

Fix: 7.x-2.26+
Fix from $1,950 2018-02-01
Kkcald HIGH 8.8
CVE-2018-0509

Cross-site request forgery (CSRF) vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attacker to hijack the authenticati…

Fix: after 0.7.21
Fix from $1,950 2018-02-01
Cipcamptiwl Firmware HIGH 8.8
CVE-2018-6408

An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrated by changing an administrat…

Mitigation only
Fix from $1,950 2018-01-30
Wf2419 Firmware HIGH 8.8
CVE-2018-6391

A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Re…

No fix yet
Fix from $1,950 2018-01-29
Jenkins HIGH 8.8
CVE-2017-1000356EPSS 7%

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: cre…

Fix: after 2.56
Fix from $1,950 2018-01-29
Airwatch HIGH 8.8
CVE-2017-4951

VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalo…

Fix: 9.1.5 / 9.2.2+
Fix from $1,950 2018-01-29
Dc38 Firmware HIGH 8.8
CVE-2018-5720

An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A Cross-site request forgery (CS…

No fix yet
Fix from $1,950 2018-01-29
Js Support Ticket HIGH 8.8
CVE-2018-6007

CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.

No fix yet
Fix from $1,950 2018-01-29
Social Media Widget HIGH 8.8
CVE-2018-6357

The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordPress has CSRF via the records…

Fix: after 3.2.5
Fix from $1,950 2018-01-27
Jenkins HIGH 8.1
CVE-2017-1000504

A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initiali…

Fix: after 2.94
Fix from $1,950 2018-01-24
Business Process Manager HIGH 8.8
CVE-2017-1769

IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized acti…

Patch available
Fix from $1,950 2018-01-24
Photography Cms HIGH 8.8
CVE-2018-5969

Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demonstrated by adding an admin acc…

No fix yet
Fix from $1,950 2018-01-24
Rsvp Invitation Online HIGH 8.8
CVE-2018-5976

Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin password.

No fix yet
Fix from $1,950 2018-01-24
Release HIGH 8.8
CVE-2018-1000013

Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attacker…

Fix: after 2.9
Fix from $1,950 2018-01-23
Translation Assistance HIGH 8.8
CVE-2018-1000014

Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability a…

Fix: after 1.15
Fix from $1,950 2018-01-23
Yiiframework HIGH 8.8
CVE-2018-6009

In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.

Patch available
Fix from $1,950 2018-01-22
Jira MEDIUM 6.5
CVE-2017-18033

The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external syste…

Fix: 7.6.1+
Fix from $1,600 2018-01-18
Prime Service Catalog HIGH 8.8
CVE-2018-0107

A vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unwanted actions on an…

Mitigation only
Fix from $1,950 2018-01-18
Contractorweb.net HIGH 8.8
CVE-2018-5329

ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attac…

No fix yet
Fix from $1,950 2018-01-15
Booking Calendar HIGH 8.8
CVE-2018-5673

An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.

No fix yet
Fix from $1,950 2018-01-13
Pinterest Feeds HIGH 8.8
CVE-2018-5656

An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php.

No fix yet
Fix from $1,950 2018-01-13