Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2020-14203 WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServle… Webfocus Business Intelligence No fix yet Fix from $1,9502020-06-22 HIGH 8.8 CVE-2019-20891 WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scr… Woocommerce 3.6.5+ Fix from $1,9502020-06-19 MEDIUM 6.1 CVE-2016-11084 An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF. Mattermost Server 2.1.0+ Fix from $1,6002020-06-19 HIGH 8.8 CVE-2017-18903 An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled. Mattermost Server 3.9.2 / 3.10.2+ Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2020-8167 A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains. Rails 5.2.4.3 / 6.0.3.1+ Fix from $1,6002020-06-19 HIGH 8.8 CVE-2019-20865 An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF. Mattermost Server 4.10.10 / 5.9.2+ Fix from $1,9502020-06-19 HIGH 8.8 CVE-2019-20841 An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for ac… Mattermost Server 5.9.7 / 5.15.4+ Fix from $1,9502020-06-19 HIGH 8.8 CVE-2020-14432 Certain NETGEAR devices are affected by CSRF. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before … Rbk752 Firmware 3.2.15.25+ Fix from $1,9502020-06-18 HIGH 8.8 CVE-2020-7503 A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to… Easergy T300 Firmware after 1.5.2 Fix from $1,9502020-06-16 HIGH 8.8 CVE-2019-19109 The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. Wpforo No fix yet Fix from $1,9502020-06-15 HIGH 8.8 CVE-2020-9042 In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the… Couchbase Server Mitigation only Fix from $1,9502020-06-08 MEDIUM 6.5 CVE-2020-13868 An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. Comments 1.5.5+ Fix from $1,6002020-06-05 MEDIUM 6.5 CVE-2020-11682 Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included… Nextgen Dvr Firmware No fix yet Fix from $1,6002020-06-04 HIGH 8.8 CVE-2020-13786 D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF. Dir 865l Firmware No fix yet Fix from $1,9502020-06-03 HIGH 8.0 CVE-2020-2196 Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions … Selenium after 3.141.59 Fix from $1,9502020-06-03 MEDIUM 6.5 CVE-2020-2192 A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove… Self Organizing Swarm Modules after 3.20 Fix from $1,6002020-06-03 HIGH 8.8 CVE-2020-13760 In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF. Joomla\! 3.9.19+ Fix from $1,9502020-06-02 HIGH 8.8 CVE-2014-8942 Lexiglot through 2014-11-20 allows CSRF. Lexiglot after 2014-11-20 Fix from $1,9502020-06-01 HIGH 8.8 CVE-2020-4018 The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site req… Crucible 4.8.1+ Fix from $1,9502020-06-01 HIGH 8.8 CVE-2020-13643 An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification… Page Builder 2.10.16+ Fix from $1,9502020-05-28 HIGH 8.8 CVE-2020-13641 An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verif… Real Time Find And Replace 4.0.2+ Fix from $1,9502020-05-28 HIGH 8.8 CVE-2020-13642 An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce … Page Builder 2.10.16+ Fix from $1,9502020-05-28 HIGH 8.8 CVE-2020-8168 We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.… Airos after 6.2.0 Fix from $1,9502020-05-26 HIGH 8.8 CVE-2020-13458 An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action. Image Resizer 2.0.9+ Fix from $1,9502020-05-25 HIGH 8.8 CVE-2020-13412 An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, lead… Controller 5.4.1204+ Fix from $1,9502020-05-22 MEDIUM 6.5 CVE-2020-13416 An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, wh… Controller 5.4.1066+ Fix from $1,6002020-05-22 MEDIUM 6.5 CVE-2020-1103 An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site… Sharepoint Enterprise Server Patch available Fix from $1,6002020-05-21 HIGH 8.8 CVE-2019-20804 Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account. Gila Cms 1.11.6+ Fix from $1,9502020-05-21 MEDIUM 6.5 CVE-2020-13231 In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change. Fedora 1.2.11+ Fix from $1,6002020-05-20 MEDIUM 6.5 CVE-2020-4286 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious… Infosphere Information Server Patch available Fix from $1,6002020-05-19