Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2020-2235 A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an at… Pipeline Maven Integration after 3.8.2 Fix from $1,6002020-08-12 HIGH 8.8 CVE-2020-7029 A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager… Aura Communication Manager 7.1 / 8.1.0.0+ Fix from $1,9502020-08-11 HIGH 8.8 CVE-2020-12781 Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery. Itop 2.7.1+ Fix from $1,9502020-08-10 HIGH 8.1 CVE-2020-16253 The PgHero gem through 2.6.0 for Ruby allows CSRF. Pghero after 2.6.0 Fix from $1,9502020-08-05 HIGH 7.6 CVE-2020-15135 save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced i… Save Server 1.0.5+ Fix from $1,9502020-08-04 HIGH 8.8 CVE-2020-5615 Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers … Calendar01 Mitigation only Fix from $1,9502020-08-04 HIGH 8.8 CVE-2020-5770 Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking leg… Trb245 Firmware No fix yet Fix from $1,9502020-08-03 MEDIUM 5.9 CVE-2020-14319 It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks ar… Amq Online 0.32.2 / 1.5.2+ Fix from $1,6002020-08-03 HIGH 8.8 CVE-2020-10984 Gambio GX before 4.0.1.0 allows admin/admin.php CSRF. Gambio Gx 4.0.1.0+ Fix from $1,9502020-07-28 HIGH 8.8 CVE-2020-5611 Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authenticatio… Social Sharing 1.2.10+ Fix from $1,9502020-07-27 HIGH 8.1 CVE-2020-15882 A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines from the MunkiReport database. Munkireport 5.6.3+ Fix from $1,9502020-07-23 MEDIUM 6.5 CVE-2020-5767 Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by t… Email Subscribers \& Newsletters No fix yet Fix from $1,6002020-07-17 HIGH 8.8 CVE-2020-11438 LibreHealth EMR v2.0.0 is affected by systemic CSRF. Librehealth Ehr No fix yet Fix from $1,9502020-07-15 MEDIUM 6.3 CVE-2020-15695 An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability. Joomla\! after 3.9.19 Fix from $1,6002020-07-15 MEDIUM 6.3 CVE-2020-15700 An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability. Joomla\! after 3.9.19 Fix from $1,6002020-07-15 HIGH 8.8 CVE-2019-12784 An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunctio… Impact 360 No fix yet Fix from $1,9502020-07-14 HIGH 8.8 CVE-2020-6289 SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to brow… Disclosure Management Mitigation only Fix from $1,9502020-07-14 HIGH 8.8 CVE-2020-15711 In MISP before 2.4.129, setting a favourite homepage was not CSRF protected. Misp 2.4.129+ Fix from $1,9502020-07-14 MEDIUM 6.5 CVE-2020-10986 A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause de… Ac15 Firmware No fix yet Fix from $1,6002020-07-13 MEDIUM 6.5 CVE-2020-15600 An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password. Cmsuno 1.6.1+ Fix from $1,6002020-07-07 MEDIUM 5.4 CVE-2020-15516 The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF. Mm Forum after 1.9.5 Fix from $1,6002020-07-07 HIGH 8.8 CVE-2020-5904 In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traff… Big Ip Access Policy Manager after 15.1.0.3 Fix from $1,9502020-07-01 HIGH 8.8 CVE-2020-5900 In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user in… Nginx Controller after 3.4.0 Fix from $1,9502020-07-01 MEDIUM 6.5 CVE-2020-15043 iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresse… Wrb303n Firmware No fix yet Fix from $1,6002020-06-29 HIGH 8.8 CVE-2020-15046 The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cg… X10drh It Bios No fix yet Fix from $1,9502020-06-24 HIGH 8.8 CVE-2020-15014 pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF. Blogcms after 2019-12-31 Fix from $1,9502020-06-24 HIGH 8.8 CVE-2020-13155 clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem… Nukeviet No fix yet Fix from $1,9502020-06-23 MEDIUM 6.5 CVE-2020-13156 modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI. Nukeviet No fix yet Fix from $1,6002020-06-23 MEDIUM 6.5 CVE-2020-13157 modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old pas… Nukeviet No fix yet Fix from $1,6002020-06-23 MEDIUM 6.5 CVE-2020-13426 The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibili… Multi Scheduler No fix yet Fix from $1,6002020-06-22