Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2020-6776 A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including ver… Praesideo Firmware after 4.41 Fix from $1,9502021-01-14 MEDIUM 6.5 CVE-2021-3133 The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages. Elementor Contact Form Db 1.6+ Fix from $1,6002021-01-12 HIGH 7.4 CVE-2021-21241 The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a independently maintained versio… Flask Security Too 3.4.5+ Fix from $1,9502021-01-11 MEDIUM 6.1 CVE-2020-23631 Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks vi… Wdja Cms No fix yet Fix from $1,6002021-01-11 HIGH 8.8 CVE-2020-23960 Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized … Fork Cms 5.8.3+ Fix from $1,9502021-01-11 MEDIUM 6.5 CVE-2020-35722 CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafte… Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 6.5 CVE-2020-36174 The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. Ninja Forms 3.4.27.1+ Fix from $1,6002021-01-06 MEDIUM 6.5 CVE-2020-7336 Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an at… Network Security Management 9.2.9.55 / 10.1.7.35+ Fix from $1,6002021-01-05 HIGH 8.8 CVE-2020-4942 IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a… Curam Social Program Management Mitigation only Fix from $1,9502021-01-04 HIGH 8.8 CVE-2020-4917 IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tran… Cloud Pak System 2.3.3.3+ Fix from $1,9502021-01-04 HIGH 8.8 CVE-2021-21495 MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI. Mk Auth after 19.01 Fix from $1,9502021-01-04 HIGH 8.8 CVE-2020-35944 An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lea… Pagelayer 1.1.2+ Fix from $1,9502021-01-01 HIGH 8.8 CVE-2020-35950 An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint). Xcloner 4.2.153+ Fix from $1,9502021-01-01 HIGH 8.8 CVE-2018-16795 OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_… Openemr No fix yet Fix from $1,9502020-12-31 HIGH 8.8 CVE-2020-35778 Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36. Gs716t Firmware 6.3.1.36+ Fix from $1,9502020-12-30 HIGH 8.8 CVE-2020-35773 The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF. Site Offline 1.4.4+ Fix from $1,9502020-12-29 MEDIUM 6.3 CVE-2020-35615 An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability. Joomla\! after 3.9.22 Fix from $1,6002020-12-28 MEDIUM 5.4 CVE-2020-26033 An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check. Zammad 3.4.1+ Fix from $1,6002020-12-28 MEDIUM 6.5 CVE-2020-35347 CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add. Cxuucms No fix yet Fix from $1,6002020-12-26 HIGH 8.8 CVE-2020-26766 A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System W… User Registration \& Login And User Management System With Admin Panel No fix yet Fix from $1,9502020-12-26 HIGH 8.8 CVE-2020-35269 Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for host… Nagios Core Mitigation only Fix from $1,9502020-12-23 HIGH 8.8 CVE-2020-35626 An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefor… Mediawiki after 1.35.1 Fix from $1,9502020-12-21 HIGH 8.0 CVE-2020-35273 EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in t… User Registration \& Login System With Admin Panel Mitigation only Fix from $1,9502020-12-21 HIGH 8.8 CVE-2020-7201 A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulne… Storeever Msl2024 Firmware 5.40 / 7.30+ Fix from $1,9502020-12-18 MEDIUM 6.5 CVE-2020-4764 IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr… Planning Analytics Patch available Fix from $1,6002020-12-18 CRITICAL 9.8 CVE-2020-8465 A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combinat… Interscan Web Security Virtual Appliance No fix yet Fix from $2,3002020-12-17 HIGH 8.8 CVE-2020-8461 A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's brow… Interscan Web Security Virtual Appliance No fix yet Fix from $1,9502020-12-17 HIGH 8.8 CVE-2020-25095 LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CSWH). If a logged-in PM user v… Platform Manager Mitigation only Fix from $1,9502020-12-17 HIGH 8.8 CVE-2020-28931 Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an … Eps Tse Server 8 Firmware No fix yet Fix from $1,9502020-12-16 MEDIUM 6.5 CVE-2020-4904 IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attack… Financial Transaction Manager For Multiplatform Patch available Fix from $1,6002020-12-16