Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2019-14481 AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a log… Netcrunch No fix yet Fix from $1,6002020-12-16 HIGH 8.8 CVE-2020-25622 An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF. N Central Mitigation only Fix from $1,9502020-12-16 HIGH 7.1 CVE-2020-14368 A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE… Che 7.14.0+ Fix from $1,9502020-12-14 HIGH 8.8 CVE-2019-19289 A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsus… Xhq 6.1.0.0+ Fix from $1,9502020-12-14 HIGH 8.8 CVE-2020-8282 A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able … Edgemax Edgepower 24v Firmware after 1.7.0 Fix from $1,9502020-12-14 HIGH 8.8 CVE-2020-28858 OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made b… Digital Asset Management after 12.0.19 Fix from $1,9502020-12-14 HIGH 8.8 CVE-2020-29254 TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site req… Tikiwiki Cms\/groupware No fix yet Fix from $1,9502020-12-11 HIGH 8.8 CVE-2020-35135 The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF. Ultimate Category Excluder 1.2+ Fix from $1,9502020-12-11 HIGH 8.1 CVE-2020-2321 A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a … Shelve Project after 3.0 Fix from $1,9502020-12-03 MEDIUM 6.3 CVE-2020-14369 This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a… Cloudforms after 5.11 Fix from $1,6002020-12-02 HIGH 8.8 CVE-2020-29458 Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem. Textpattern No fix yet Fix from $1,9502020-12-02 MEDIUM 6.5 CVE-2020-4127 HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under anothe… Hcl Domino 9.0.1 / 10.0.1+ Fix from $1,6002020-11-30 MEDIUM 6.5 CVE-2020-17901 Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user. Pbootcms No fix yet Fix from $1,6002020-11-30 HIGH 8.8 CVE-2020-7780 This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before … Akka Http Session after 0.5.11 Fix from $1,9502020-11-27 HIGH 8.8 CVE-2020-26936 Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack. Data Engineering 1.1+ Fix from $1,9502020-11-26 HIGH 8.8 CVE-2020-13620 Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to p… Fastgate Gpon Fga2130fwb Firmware after 2020-05-26 Fix from $1,9502020-11-24 MEDIUM 6.5 CVE-2020-25472 SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users. News Script Php Pro Mitigation only Fix from $1,6002020-11-24 MEDIUM 6.5 CVE-2020-5641 Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication… Gs108ev3 Firmware after 2.06.10 Fix from $1,6002020-11-24 HIGH 8.8 CVE-2020-28649 The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file. Child Theme Creator 1.5.2+ Fix from $1,9502020-11-16 HIGH 8.8 CVE-2020-7332 Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows … Endpoint Security 10.6.1+ Fix from $1,9502020-11-12 HIGH 8.8 CVE-2019-7357 Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins. Subrion Cms Patch available Fix from $1,9502020-11-10 HIGH 8.8 CVE-2020-27146 The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated … Iprocess Workspace Browser after 11.6.0 Fix from $1,9502020-11-10 HIGH 8.8 CVE-2020-27016 Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability which could… Interscan Messaging Security Virtual Appliance after 9.1 Fix from $1,9502020-11-09 HIGH 8.8 CVE-2020-15259 ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or c… Ad\/ldap Connector 5.0.13+ Fix from $1,9502020-11-06 HIGH 8.8 CVE-2020-27692 The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management portal. At… Verve Connect Vh510 Firmware 1.0.1.6l0516+ Fix from $1,9502020-11-04 MEDIUM 6.5 CVE-2020-22273 Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings) Neoflex Video Subscription System Mitigation only Fix from $1,6002020-11-04 HIGH 8.8 CVE-2020-11485 NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) vulnerability in the AMI BMC … Bmc Firmware 3.38.30+ Fix from $1,9502020-10-29 HIGH 8.8 CVE-2020-16256 The API on Winston 1.5.4 devices is vulnerable to CSRF. Winston Firmware No fix yet Fix from $1,9502020-10-28 HIGH 8.8 CVE-2020-27975 osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF. Oscommerce 1.0.5.4+ Fix from $1,9502020-10-28 HIGH 8.8 CVE-2020-18129 A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php. Eyoucms No fix yet Fix from $1,9502020-10-22