Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2021-20687 Cross-site request forgery (CSRF) vulnerability in Kagemai 0.8.8 allows remote attackers to hijack the authentication of administrators via unspecifi… Kagemai Mitigation only Fix from $1,9502021-04-07 HIGH 8.8 CVE-2021-30147 DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php. Radius Manager No fix yet Fix from $1,9502021-04-07 HIGH 8.1 CVE-2021-24174 The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such a… Database Backups after 1.2.2.6 Fix from $1,9502021-04-05 HIGH 8.8 CVE-2021-24159 Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScr… Contact Form 7 after 3.1.9 Fix from $1,9502021-04-05 HIGH 8.8 CVE-2021-24161 In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip … Responsive Menu 4.0.4+ Fix from $1,9502021-04-05 HIGH 8.8 CVE-2021-24162 In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all ne… Responsive Menu 4.0.4+ Fix from $1,9502021-04-05 MEDIUM 5.4 CVE-2021-24166 The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had n… Ninja Forms 3.4.34+ Fix from $1,6002021-04-05 MEDIUM 6.1 CVE-2021-24173 The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update t… Vm Backups after 1.0 Fix from $1,6002021-04-05 HIGH 8.8 CVE-2021-29660 A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the … Opc Toolbox after 4.10.1.13035 Fix from $1,9502021-04-02 HIGH 8.8 CVE-2021-25924 In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoin… Gocd 21.2.0+ Fix from $1,9502021-04-01 MEDIUM 6.5 CVE-2021-29349 Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The application fails… Mahara No fix yet Fix from $1,6002021-03-31 HIGH 8.8 CVE-2021-21629 A cross-site request forgery (CSRF) vulnerability in Jenkins Build With Parameters Plugin 1.5 and earlier allows attackers to build a project with at… Build With Parameters after 1.5 Fix from $1,9502021-03-30 HIGH 8.8 CVE-2021-21633 A cross-site request forgery (CSRF) vulnerability in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers to connect to an attack… Owasp Dependency Track after 3.1.0 Fix from $1,9502021-03-30 HIGH 8.8 CVE-2021-21638 A cross-site request forgery (CSRF) vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers to connect to an atta… Team Foundation Server after 5.157.1 Fix from $1,9502021-03-30 HIGH 8.8 CVE-2020-19639 Cross Site Request Forgery (CSRF) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B, via all fields to WebUI. Wifi Mini Spy 1080p Hd Security Ip Camera Firmware Mitigation only Fix from $1,9502021-03-30 HIGH 8.8 CVE-2020-36283 HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated … Omnikey 5427 Firmware Mitigation only Fix from $1,9502021-03-24 HIGH 8.8 CVE-2021-21627 A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to stop hypervisor domains. Libvirt Agents after 1.9.0 Fix from $1,9502021-03-18 HIGH 8.8 CVE-2020-29553 The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (… Grav Cms after 1.6.31 Fix from $1,9502021-03-15 HIGH 8.8 CVE-2020-24983 An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses a POST req… Espressreports Es No fix yet Fix from $1,9502021-03-11 HIGH 8.8 CVE-2020-24984 An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin lev… Espressreports Es No fix yet Fix from $1,9502021-03-11 MEDIUM 6.5 CVE-2020-14989 An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended. Experience Manager after 14.2.2 Fix from $1,6002021-03-11 HIGH 8.8 CVE-2020-35223 The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omittin… Gs116e Firmware Mitigation only Fix from $1,9502021-03-10 HIGH 8.8 CVE-2020-27574 Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions… Rumpus Mitigation only Fix from $1,9502021-03-08 HIGH 8.8 CVE-2020-29030 Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: S… Gatemanager Firmware 9.4.621054022+ Fix from $1,9502021-03-05 HIGH 8.8 CVE-2021-26961 A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2… Airwave 8.2.12.0+ Fix from $1,9502021-03-05 HIGH 8.8 CVE-2021-26960 A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2… Airwave 8.2.12.0+ Fix from $1,9502021-03-05 HIGH 8.8 CVE-2021-27927 In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthent… Zabbix after 5.2.3 Fix from $1,9502021-03-03 HIGH 8.8 CVE-2021-27885 usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism. E107 after 2.3.0 Fix from $1,9502021-03-02 HIGH 8.1 CVE-2021-1227 A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery… Nx Os Mitigation only Fix from $1,9502021-02-24 HIGH 8.8 CVE-2021-21617 A cross-site request forgery (CSRF) vulnerability in Jenkins Configuration Slicing Plugin 1.51 and earlier allows attackers to apply different slice … Configuration Slicing after 1.51 Fix from $1,9502021-02-24