Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2020-27997 An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g.… Smartstorenet 4.1.0+ Fix from $1,9502021-02-19 HIGH 7.5 CVE-2021-26296 In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptograph… Myfaces after 2.3.7 Fix from $1,9502021-02-19 HIGH 8.8 CVE-2020-36247 Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF. Open Ondemand 1.5.7 / 1.6.22+ Fix from $1,9502021-02-19 HIGH 8.8 CVE-2021-20073 Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries. M\!dge Firmware Mitigation only Fix from $1,9502021-02-16 MEDIUM 6.5 CVE-2021-20646 Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentication of administrators and ex… Wrc 300febk A Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2021-20647 Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentication of administrators and ex… Wrc 300febk S Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2021-20650 Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authentication of administrators and … Ncc Ewf100rmwh2 Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2021-20636 Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via … Lan W300n\/pr5b Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2021-20641 Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a … Lan W300n\/rs Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2020-13186 An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacke… Cloud Access Connector after 31 Fix from $1,6002021-02-11 HIGH 8.8 CVE-2021-20403 IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious … Security Verify Information Queue Mitigation only Fix from $1,9502021-02-11 MEDIUM 6.5 CVE-2020-35943 A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF… Nextgen Gallery 3.5.0+ Fix from $1,6002021-02-09 HIGH 8.8 CVE-2020-35942 A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via se… Nextgen Gallery 3.5.0+ Fix from $1,9502021-02-09 HIGH 8.8 CVE-2020-13460 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA. Securetrack Mitigation only Fix from $1,9502021-02-09 MEDIUM 6.5 CVE-2021-22500 Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulne… Application Performance Management Mitigation only Fix from $1,6002021-02-06 HIGH 8.8 CVE-2021-20652 Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administ… Name Directory after 1.17.4 Fix from $1,9502021-02-05 MEDIUM 6.5 CVE-2020-9388 CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary cod… Squaredup 4.6+ Fix from $1,6002021-02-03 HIGH 8.8 CVE-2021-25765 In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible. Youtrack 2020.4.4701+ Fix from $1,9502021-02-03 HIGH 8.8 CVE-2020-24271 A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callba… Easycms No fix yet Fix from $1,9502021-02-01 HIGH 8.8 CVE-2020-28403 A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privi… Star Mitigation only Fix from $1,9502021-01-29 HIGH 8.8 CVE-2020-29004 The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack. Mediawiki after 1.35 Fix from $1,9502021-01-29 HIGH 8.8 CVE-2020-13569 A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f… Openemr No fix yet Fix from $1,9502021-01-28 HIGH 8.8 CVE-2021-20621 Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier al… Wg2600hp Firmware after 1.0.2 Fix from $1,9502021-01-28 HIGH 8.8 CVE-2020-35239 A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CS… Cakephp after 4.1.3 Fix from $1,9502021-01-26 HIGH 8.8 CVE-2020-12511 Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface. Io Link Master 4 Eip Firmware after 1.5.48 Fix from $1,9502021-01-22 HIGH 8.8 CVE-2021-1257 A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross… Catalyst Center 2.1.1.0 / 5.7.6+ Fix from $1,9502021-01-20 HIGH 8.8 CVE-2020-28452 This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package com.softwaremill.akka-http-ses… Akka Http Session 0.6.1+ Fix from $1,9502021-01-20 HIGH 8.8 CVE-2020-35217 Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSR… Vert.x Web Patch available Fix from $1,9502021-01-20 HIGH 8.8 CVE-2020-23342EPSS 12% A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. Anchor Cms No fix yet Fix from $1,9502021-01-19 MEDIUM 6.8 CVE-2020-23522 Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter. Pixelimity No fix yet Fix from $1,6002021-01-19