Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.1 CVE-2020-4617 IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac… Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 CRITICAL 9.6 CVE-2020-15182 The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects vers… Soy Cms 2.0.0.4 / 3.0.2.328+ Fix from $2,3002020-09-17 HIGH 8.8 CVE-2020-24373 A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3. Freebox Revolution Firmware 4.2.3+ Fix from $1,9502020-09-16 HIGH 8.8 CVE-2020-13259 A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to… Secflow 1v Firmware No fix yet Fix from $1,9502020-09-16 MEDIUM 6.5 CVE-2020-25015 A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices wa… Platinum 4410 Firmware No fix yet Fix from $1,6002020-09-16 HIGH 8.8 CVE-2020-2268 A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any a… MongoDB after 1.3 Fix from $1,9502020-09-16 HIGH 8.8 CVE-2020-25453EPSS 6% An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution. Blackcat Cms 1.4+ Fix from $1,9502020-09-15 HIGH 8.8 CVE-2020-23451 Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function. Spiceworks after 7.5.00107 Fix from $1,9502020-09-15 HIGH 8.8 CVE-2020-10229 A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding use… Vtenext No fix yet Fix from $1,9502020-09-14 HIGH 8.8 CVE-2020-23824 ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Admi… Mail Server No fix yet Fix from $1,9502020-09-11 MEDIUM 6.5 CVE-2018-19948 The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could… Helpdesk 3.0.3+ Fix from $1,6002020-09-11 HIGH 8.8 CVE-2020-25252 An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1… Onbase after 20.3.10.1000 Fix from $1,9502020-09-11 MEDIUM 6.5 CVE-2020-24739 A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request nor… Icms No fix yet Fix from $1,6002020-09-10 HIGH 8.1 CVE-2020-15789 A vulnerability has been identified in Polarion Subversion Webclient (All versions). The web interface could allow a Cross-Site Request Forgery (CSRF… Polarion Subversion Webclient Mitigation only Fix from $1,9502020-09-09 HIGH 7.1 CVE-2020-23830 A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to den… Stock Management System No fix yet Fix from $1,9502020-09-02 HIGH 8.8 CVE-2020-16208 The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by lurin… N Tron 702 W Firmware No fix yet Fix from $1,9502020-09-01 HIGH 8.8 CVE-2020-25070 USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature. Usvn 1.0.10+ Fix from $1,9502020-09-01 HIGH 8.8 CVE-2020-5776EPSS 15% Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF… Magmi Mitigation only Fix from $1,9502020-09-01 HIGH 8.8 CVE-2020-23836 A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remo… Warehouse Inventory System after 2020-08-10 Fix from $1,9502020-09-01 HIGH 8.8 CVE-2020-2240 A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts. Database after 1.6 Fix from $1,9502020-09-01 HIGH 8.8 CVE-2020-2241 A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified dat… Database after 1.6 Fix from $1,9502020-09-01 HIGH 8.1 CVE-2020-15156 In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their… Blog Comments 0.7.0+ Fix from $1,9502020-08-26 HIGH 8.8 CVE-2020-5922 In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Si… Big Ip Access Policy Manager 12.1.5.2 / 13.1.3.4+ Fix from $1,9502020-08-26 HIGH 8.8 CVE-2020-14043 ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to down… Codiad No fix yet Fix from $1,9502020-08-24 HIGH 8.1 CVE-2020-19886 DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu. Dbhcms No fix yet Fix from $1,9502020-08-24 HIGH 8.8 CVE-2020-19889 DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user. Dbhcms No fix yet Fix from $1,9502020-08-24 HIGH 8.0 CVE-2020-15151 OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attac… Openmage Long Term Support 19.4.6 / 20.0.2+ Fix from $1,9502020-08-20 MEDIUM 6.5 CVE-2020-12480 In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that… Play Framework after 2.8.1 Fix from $1,6002020-08-17 MEDIUM 6.5 CVE-2016-11085 php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_… Quiz And Survey Master 4.7.9+ Fix from $1,6002020-08-16 HIGH 7.6 CVE-2020-7304 Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to e… Data Loss Prevention 11.3.28 / 11.4.200+ Fix from $1,9502020-08-13