Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2021-20126 Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent … Vigorconnect No fix yet Fix from $1,9502021-10-13 HIGH 8.8 CVE-2021-20831 Cross-site request forgery (CSRF) vulnerability in OG Tags versions prior to 2.0.2 allows a remote attacker to hijack the authentication of administr… Og Tags 2.0.2+ Fix from $1,9502021-10-13 HIGH 8.8 CVE-2021-20795 Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack t… Remote Service Manager Mitigation only Fix from $1,9502021-10-13 MEDIUM 5.4 CVE-2021-24683 The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them,… Weather Effect 1.3.4+ Fix from $1,6002021-10-11 HIGH 8.8 CVE-2021-24711 The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable … Software License Manager 4.5.1+ Fix from $1,9502021-10-11 HIGH 8.8 CVE-2021-41916 A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profil… Webtareas after 2.4 Fix from $1,9502021-10-08 HIGH 8.8 CVE-2021-20489 IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and … Sterling File Gateway after 6.1.0.3 Fix from $1,9502021-10-07 MEDIUM 6.5 CVE-2020-21658 A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a crafted URL. Wdja Cms No fix yet Fix from $1,6002021-10-06 HIGH 8.8 CVE-2021-29837 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to exe… Sterling B2b Integrator after 6.1.0.3 Fix from $1,9502021-10-06 HIGH 8.8 CVE-2021-41113 TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the new TYPO3 v11 feature tha… TYPO3 11.5.0+ Fix from $1,9502021-10-05 HIGH 8.1 CVE-2021-35491 A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via th… Streaming Engine 4.8.14+ Fix from $1,9502021-10-05 HIGH 8.8 CVE-2020-21386 A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges. Maccms No fix yet Fix from $1,9502021-10-04 HIGH 8.8 CVE-2021-41295 ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious we… Ecs Router Controller Ecs Firmware Mitigation only Fix from $1,9502021-09-30 HIGH 8.8 CVE-2021-41764 A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place w… Streama after 1.10.3 Fix from $1,9502021-09-29 HIGH 8.8 CVE-2021-34636 The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in… Countdown And Countup\, Woocommerce Sales Timer after 1.5.7 Fix from $1,9502021-09-28 HIGH 8.8 CVE-2020-20693 A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts. Gila Cms No fix yet Fix from $1,9502021-09-27 HIGH 8.8 CVE-2021-36876 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin adminis… Ulisting after 2.0.5 Fix from $1,9502021-09-27 MEDIUM 6.5 CVE-2021-36877 Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles. Ulisting after 2.0.5 Fix from $1,6002021-09-27 HIGH 8.8 CVE-2021-40108 An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/even… Concrete Cms 8.5.6+ Fix from $1,9502021-09-27 HIGH 8.8 CVE-2021-3819 firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) Firefly Iii 5.6.1+ Fix from $1,9502021-09-27 MEDIUM 6.5 CVE-2021-31604 furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client. Openvpn Monitor after 1.1.3 Fix from $1,6002021-09-27 HIGH 8.1 CVE-2020-20514 A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users. Maccms No fix yet Fix from $1,9502021-09-24 HIGH 8.8 CVE-2020-19951 A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application. Yzmcms No fix yet Fix from $1,9502021-09-23 MEDIUM 6.5 CVE-2021-29816 IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery which could allow an attacker… Jazz For Service Management Patch available Fix from $1,6002021-09-23 MEDIUM 5.4 CVE-2021-22953 A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Cr… Concrete Cms after 8.5.5 Fix from $1,6002021-09-23 MEDIUM 5.4 CVE-2021-22949 A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space… Concrete Cms after 8.5.5 Fix from $1,6002021-09-23 MEDIUM 6.5 CVE-2021-22950 Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery:… Concrete Cms 8.5.6+ Fix from $1,6002021-09-23 HIGH 8.8 CVE-2021-41083 Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully crafted web page via email, S… Dada Mail 11.16.0+ Fix from $1,9502021-09-20 MEDIUM 5.4 CVE-2021-24618 The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scri… Donate With Qrcode 1.4.5+ Fix from $1,6002021-09-20 HIGH 8.1 CVE-2021-24636 The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactiv… Print My Blog 3.4.2+ Fix from $1,9502021-09-20