Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.1 CVE-2021-24639 The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which … Omgf 4.5.4+ Fix from $1,9502021-09-20 MEDIUM 5.4 CVE-2021-24584 The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with t… Timetable And Event Schedule 2.4.2+ Fix from $1,6002021-09-20 HIGH 8.8 CVE-2021-40965 A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload fil… Tiny File Manager after 2.4.6 Fix from $1,9502021-09-15 HIGH 8.8 CVE-2020-21126 MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo. Metinfo No fix yet Fix from $1,9502021-09-15 HIGH 8.8 CVE-2021-39209 GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Fo… Glpi 9.5.6+ Fix from $1,9502021-09-15 HIGH 8.8 CVE-2020-19159 Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action… Laiketui No fix yet Fix from $1,9502021-09-15 HIGH 8.8 CVE-2021-23026 BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x an… Big Ip Access Policy Manager after 16.0.1.1 Fix from $1,9502021-09-14 MEDIUM 6.5 CVE-2020-21081 A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted … Maccms No fix yet Fix from $1,6002021-09-14 HIGH 7.5 CVE-2021-23050 On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on all versions before 3.5.0, whe… Big Ip Advanced Web Application Firewall 3.5.0 / 15.1.3.1+ Fix from $1,9502021-09-14 HIGH 8.8 CVE-2021-37201 A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). The web interface of affected devices is vulnerable to a Cross-Site Reque… Sinec Network Management System 1.0+ Fix from $1,9502021-09-14 HIGH 8.8 CVE-2020-20671 A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account. Kitecms No fix yet Fix from $1,9502021-09-13 HIGH 8.8 CVE-2021-24620 The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable D… Simple E Commerce Shopping Cart after 2.2.5 Fix from $1,9502021-09-13 MEDIUM 6.8 CVE-2021-24490 The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arb… Email Artillery after 4.1 Fix from $1,6002021-09-13 HIGH 8.8 CVE-2021-24491 The Fileviewer WordPress plugin through 2.2 does not have CSRF checks in place when performing actions such as upload and delete files. As a result, … Fileviewer after 2.2 Fix from $1,9502021-09-13 HIGH 8.8 CVE-2020-19280 Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations. Jeesns No fix yet Fix from $1,9502021-09-09 MEDIUM 6.5 CVE-2020-19264 A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/ApiAdminUser/itemAdd. Mipcms No fix yet Fix from $1,6002021-09-09 MEDIUM 5.7 CVE-2020-19268 A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator … Dswjcms No fix yet Fix from $1,6002021-09-09 HIGH 8.8 CVE-2020-19263 A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily escalate user privileges to administrator via index.php?s=/user/… Mipcms No fix yet Fix from $1,9502021-09-09 MEDIUM 6.5 CVE-2021-38721 FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability Fuel Cms Patch available Fix from $1,6002021-09-09 HIGH 8.8 CVE-2021-23404 This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request … Sqlite Web No fix yet Fix from $1,9502021-09-08 HIGH 8.8 CVE-2021-38705 ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticated user following a malicious … Cliniccases No fix yet Fix from $1,9502021-09-07 HIGH 8.8 CVE-2021-39197 better_errors is an open source replacement for the standard Rails error page with more information rich error pages. It is also usable outside of Ra… Better Errors 2.8.0+ Fix from $1,9502021-09-07 MEDIUM 6.5 CVE-2019-5318 A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6.x.x.x: all versions, 8.x.x.x… Arubaos 8.8.0.0+ Fix from $1,6002021-09-07 HIGH 8.1 CVE-2021-37725 A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software versio… Sd Wan 2.2.0.4 / 8.3.0.15+ Fix from $1,9502021-09-07 MEDIUM 5.4 CVE-2021-24611 The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, … Keyword Meta after 3.0 Fix from $1,6002021-09-06 MEDIUM 6.5 CVE-2020-20343 WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arb… Wtcms No fix yet Fix from $1,6002021-09-01 HIGH 8.8 CVE-2020-19047 Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/ind… Iwebshop No fix yet Fix from $1,9502021-08-31 HIGH 8.8 CVE-2021-21678 Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins. Saml after 2.0.7 Fix from $1,9502021-08-31 HIGH 8.8 CVE-2021-21679 Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenki… Azure Ad after 179.vf6841393099e Fix from $1,9502021-08-31 MEDIUM 6.8 CVE-2021-39133 Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, a user w… Rundeck 3.3.14 / 3.4.3+ Fix from $1,6002021-08-30