Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2020-18460 Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Admin&m=content. 711cms No fix yet Fix from $1,9502021-08-12 MEDIUM 6.8 CVE-2020-18454 Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html. Bycms No fix yet Fix from $1,6002021-08-12 MEDIUM 6.8 CVE-2020-18457 Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucenter/add.html. Bycms No fix yet Fix from $1,6002021-08-12 MEDIUM 6.5 CVE-2020-25562 In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critical application forms lik… Sapphireims No fix yet Fix from $1,6002021-08-11 HIGH 8.0 CVE-2021-32122 Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, and EX6130 before … Ex3700 Firmware 1.0.0.44 / 1.0.0.64+ Fix from $1,9502021-08-11 MEDIUM 6.5 CVE-2021-29400 A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP s… My Smtp Contact No fix yet Fix from $1,6002021-08-10 HIGH 8.8 CVE-2021-37366 CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker c… Ctparental 4.45.03+ Fix from $1,9502021-08-10 MEDIUM 6.5 CVE-2021-24467 The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in adm… Leaflet Map 3.0.0+ Fix from $1,6002021-08-09 HIGH 8.1 CVE-2021-24500 Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object refer… Workreap 2.2.2+ Fix from $1,9502021-08-09 MEDIUM 6.5 CVE-2020-21358 A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users. Wage Cms No fix yet Fix from $1,6002021-08-06 HIGH 8.8 CVE-2020-18694 Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the component "/a… Ignitedcms No fix yet Fix from $1,9502021-08-06 HIGH 8.8 CVE-2021-37381 Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos through CSRF. For example: any… Graduate Management Information System No fix yet Fix from $1,9502021-08-06 HIGH 8.8 CVE-2021-34633 The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php fil… Youtube Feeder after 2.0.1 Fix from $1,9502021-08-05 HIGH 8.8 CVE-2021-34634 The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.p… Sola Newsletters after 4.0.23 Fix from $1,9502021-08-05 HIGH 8.8 CVE-2021-34631 The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in the ~/news-plugin.php file wh… Newsplugin after 1.0.18 Fix from $1,9502021-08-05 HIGH 8.8 CVE-2021-23849 A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another us… Cpp4 Firmware Mitigation only Fix from $1,9502021-08-05 HIGH 7.5 CVE-2021-33338 The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in… Digital Experience Platform after 7.3.2 Fix from $1,9502021-08-04 HIGH 8.8 CVE-2021-34628 The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-… Admin Custom Login after 3.2.7 Fix from $1,9502021-08-02 HIGH 8.8 CVE-2021-34632 The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ~/seo-backlinks.php file whic… Seo Backlinks after 4.0.1 Fix from $1,9502021-08-02 HIGH 8.8 CVE-2021-34637 The Post Index WordPress plugin is vulnerable to Cross-Site Request Forgery via the OptionsPage function found in the ~/php/settings.php file which a… Post Index after 0.7.5 Fix from $1,9502021-08-02 HIGH 8.8 CVE-2021-29757 IBM QRadar User Behavior Analytics 4.1.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthori… Qradar User Behavior Analytics Patch available Fix from $1,9502021-08-02 MEDIUM 6.1 CVE-2021-24504 The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payl… Wp Learn Manager after 1.1.2 Fix from $1,6002021-08-02 MEDIUM 6.1 CVE-2021-24477 The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a page, leading to a Stored Cr… Migrate Users after 1.0.1 Fix from $1,6002021-08-02 HIGH 8.8 CVE-2021-20783 Cross-site request forgery (CSRF) vulnerability in Optical BB unit E-WMTA2.3 allows a remote attacker to hijack the authentication of administrators … Optical Bb Unit E Wmta Firmware Mitigation only Fix from $1,9502021-07-30 HIGH 8.8 CVE-2020-18157 Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php. Metinfo No fix yet Fix from $1,9502021-07-30 HIGH 8.8 CVE-2020-22761 Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php. Flatpress Patch available Fix from $1,9502021-07-30 HIGH 8.8 CVE-2021-32776 Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows serv… Itop 2.7.4+ Fix from $1,9502021-07-21 MEDIUM 6.5 CVE-2021-21407 Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop … Itop 2.7.4+ Fix from $1,6002021-07-21 HIGH 8.8 CVE-2021-34619 The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and in… Stock Manager For Woocommerce after 2.5.7 Fix from $1,9502021-07-21 HIGH 8.8 CVE-2020-15660 Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically p… Geckodriver 0.27.0+ Fix from $1,9502021-07-20