Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2021-24179 The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue,… Business Directory Plugin Easy Listing Directories 5.11+ Fix from $1,9502021-05-06 MEDIUM 6.5 CVE-2021-24249 The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issu… Business Directory Plugin Easy Listing Directories 5.11.2+ Fix from $1,6002021-05-06 HIGH 8.8 CVE-2020-23127 Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user. Chamilo Lms Patch available Fix from $1,9502021-05-06 HIGH 8.8 CVE-2020-36334 themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database. Themegrill Demo Importer 1.6.3+ Fix from $1,9502021-05-05 HIGH 8.8 CVE-2021-29238 CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF). Automation Server 1.16.0+ Fix from $1,9502021-05-03 HIGH 8.8 CVE-2021-30224 Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials. Rukovoditel Patch available Fix from $1,9502021-04-29 MEDIUM 6.1 CVE-2021-28280 CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML Phpfusion Patch available Fix from $1,6002021-04-29 HIGH 8.8 CVE-2020-21989 HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP req… Homeautomation No fix yet Fix from $1,9502021-04-27 HIGH 8.0 CVE-2020-22000 HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a … Homeautomation No fix yet Fix from $1,9502021-04-27 HIGH 8.8 CVE-2021-31760EPSS 8% Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature. Webmin No fix yet Fix from $1,9502021-04-25 HIGH 8.8 CVE-2021-31762EPSS 9% Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse … Webmin No fix yet Fix from $1,9502021-04-25 HIGH 8.8 CVE-2021-31584 Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrati… Next Generation Communication Platform No fix yet Fix from $1,9502021-04-23 MEDIUM 5.4 CVE-2021-21644 A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration f… Config File Provider after 3.7.0 Fix from $1,6002021-04-21 HIGH 8.8 CVE-2021-27181 An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to … Mdaemon 20.0.4+ Fix from $1,9502021-04-14 HIGH 8.8 CVE-2021-31152 Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change pas… Ac1200 Re018 Firmware No fix yet Fix from $1,9502021-04-14 HIGH 8.1 CVE-2021-29436 Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In Time Tracker before version 1.19.27.5431 a Cross site re… Time Tracker 1.19.27.5431+ Fix from $1,9502021-04-13 MEDIUM 6.5 CVE-2021-29435 trestle-auth is an authentication plugin for the Trestle admin framework. A vulnerability in trestle-auth versions 0.4.0 and 0.4.1 allows an attacker… Trestle Auth Patch available Fix from $1,6002021-04-13 MEDIUM 6.5 CVE-2021-21729 Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization oper… Zxhn H168n Firmware Mitigation only Fix from $1,6002021-04-13 HIGH 8.1 CVE-2021-21731 A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whe… Zxcloud Irai 6.03.04+ Fix from $1,9502021-04-13 HIGH 8.8 CVE-2021-29054 Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface. This affects Papoo CMS Light through 21.02 and Papo… Papoo after 21.02 Fix from $1,9502021-04-13 HIGH 8.1 CVE-2021-24230 The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make … Patreon Wordpress 1.7.0+ Fix from $1,9502021-04-12 MEDIUM 6.5 CVE-2021-24231 The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make … Patreon Wordpress 1.7.0+ Fix from $1,6002021-04-12 HIGH 8.8 CVE-2021-24218 The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF … Facebook 3.0.4+ Fix from $1,9502021-04-12 HIGH 8.8 CVE-2020-21884 Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/netw… Unibox U50 Firmware Mitigation only Fix from $1,9502021-04-09 MEDIUM 5.4 CVE-2021-25326 Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connect… Rn510 Firmware No fix yet Fix from $1,6002021-04-09 MEDIUM 6.5 CVE-2021-25327 Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-… Rn510 Firmware No fix yet Fix from $1,6002021-04-09 MEDIUM 6.5 CVE-2021-22512 Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects versio… Application Automation Tools after 6.7 Fix from $1,6002021-04-08 CRITICAL 9.8 CVE-2020-23426 zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for … Zzcms No fix yet Fix from $2,3002021-04-08 MEDIUM 6.5 CVE-2021-30112 Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application r… Enterprise Resource Planning No fix yet Fix from $1,6002021-04-08 MEDIUM 6.5 CVE-2021-30114 Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request thr… Enterprise Resource Planning No fix yet Fix from $1,6002021-04-08