Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2020-24033 An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allo… S3900 24t4s Firmware after 1.7.0 Fix from $1,9502020-10-22 HIGH 8.8 CVE-2020-3456 A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cros… Firepower Extensible Operating System Patch available Fix from $1,9502020-10-21 MEDIUM 6.5 CVE-2020-5790 Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into cli… Nagios Xi No fix yet Fix from $1,6002020-10-20 HIGH 8.8 CVE-2020-12502 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES… Es7510 Xt Firmware No fix yet Fix from $1,9502020-10-15 HIGH 8.8 CVE-2020-5642 Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote attackers to hijack the authentic… Live Chat Live Support after 3.1.0 Fix from $1,9502020-10-15 MEDIUM 6.5 CVE-2020-4773 A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a u… Curam Social Program Management Mitigation only Fix from $1,6002020-10-12 HIGH 8.8 CVE-2020-26912 Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.… D6200 Firmware 1.0.0.42 / 1.0.0.66+ Fix from $1,9502020-10-09 HIGH 8.8 CVE-2020-26522 A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack t… Garfield Petshop after 2020-10-01 Fix from $1,9502020-10-09 HIGH 8.8 CVE-2020-26802 forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=saveinfo via a GET request to … Formalms No fix yet Fix from $1,9502020-10-08 MEDIUM 6.5 CVE-2020-2295 A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds … Maven Cascade Release after 1.3.2 Fix from $1,6002020-10-08 HIGH 7.1 CVE-2020-25263 PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be … Pyrocms No fix yet Fix from $1,9502020-10-08 MEDIUM 6.5 CVE-2020-25986 A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user. Monocms No fix yet Fix from $1,6002020-10-06 HIGH 8.1 CVE-2020-12123 CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, beca… Wn530h4 Firmware Mitigation only Fix from $1,9502020-10-02 HIGH 8.8 CVE-2020-5786EPSS 9% Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legi… Trb245 Firmware No fix yet Fix from $1,9502020-10-01 MEDIUM 6.5 CVE-2020-24570 An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24pr… Mbconnect24 after 2.6.1 Fix from $1,6002020-09-30 HIGH 8.0 CVE-2020-13658 In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges wit… Lansweeper No fix yet Fix from $1,9502020-09-30 MEDIUM 6.5 CVE-2020-25142 An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable if any links and forms lack an unpredictable C… Observium Mitigation only Fix from $1,6002020-09-25 HIGH 8.8 CVE-2020-23837 A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) us… Multi User No fix yet Fix from $1,9502020-09-25 MEDIUM 6.5 CVE-2020-12281 iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to create a new user via /index.php. Ismartgate Pro Firmware No fix yet Fix from $1,6002020-09-24 HIGH 8.8 CVE-2020-12282 iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible via /index.php. (This can be … Ismartgate Pro Firmware No fix yet Fix from $1,9502020-09-24 MEDIUM 6.5 CVE-2020-12840 ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php Ismartgate Pro Firmware No fix yet Fix from $1,6002020-09-24 MEDIUM 6.5 CVE-2020-12841 ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php Ismartgate Pro Firmware No fix yet Fix from $1,6002020-09-24 MEDIUM 6.5 CVE-2020-12280 iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to open/close a specified garage door/gate via /isg/opendoor.php. Ismartgate Pro Firmware No fix yet Fix from $1,6002020-09-24 MEDIUM 5.4 CVE-2020-5783 In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms. Helios Glinq No fix yet Fix from $1,6002020-09-23 HIGH 8.8 CVE-2020-2280 A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execute arbitrary code. Warnings after 5.0.1 Fix from $1,9502020-09-23 MEDIUM 5.4 CVE-2020-2281 A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock… Lockable Resources after 2.8 Fix from $1,6002020-09-23 HIGH 8.8 CVE-2020-3135 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated, remote attacker t… Unified Communications Manager 11.5+ Fix from $1,9502020-09-23 MEDIUM 6.5 CVE-2020-3124 A vulnerability in the web-based interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) could allow an unauthenticated, remote attacke… Hosted Collaboration Mediation Fulfillment 12.5+ Fix from $1,6002020-09-23 HIGH 8.8 CVE-2019-16009 A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request … iOS 16.1.1+ Fix from $1,9502020-09-23 HIGH 8.8 CVE-2020-14025 Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making… Ozeki Ng Sms Gateway after 4.17.6 Fix from $1,9502020-09-22