Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2018-21037 Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI. Subrion after 4.1.5 Fix from $1,9502020-03-17 HIGH 8.8 CVE-2020-9346 Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changin… Manageengine Password Manager Pro 10.4+ Fix from $1,9502020-03-16 HIGH 8.8 CVE-2020-6585 Nagios Log Server 2.1.3 has CSRF. Nagios No fix yet Fix from $1,9502020-03-16 HIGH 8.8 CVE-2020-10241 An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF. Joomla\! 3.9.16+ Fix from $1,9502020-03-16 HIGH 8.8 CVE-2020-10568 The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution i… Sitepress Multilingual Cms 4.3.7+ Fix from $1,9502020-03-14 MEDIUM 6.5 CVE-2019-13199 Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this v… Ecosys M5526cdw Firmware Mitigation only Fix from $1,6002020-03-13 MEDIUM 6.5 CVE-2019-13170 Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this v… Phaser 3320 Firmware Mitigation only Fix from $1,6002020-03-13 HIGH 8.8 CVE-2019-13395 The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA… Cg3700b Firmware No fix yet Fix from $1,9502020-03-13 HIGH 8.8 CVE-2020-10540 Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules. Webuntis 2020.9.6+ Fix from $1,9502020-03-13 HIGH 8.8 CVE-2019-17653 A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to… Fortisiem Mitigation only Fix from $1,9502020-03-12 MEDIUM 6.5 CVE-2020-10501 CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted req… Phpkb No fix yet Fix from $1,6002020-03-12 MEDIUM 6.5 CVE-2020-10497 CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a category via a crafted request. Phpkb No fix yet Fix from $1,6002020-03-12 MEDIUM 6.5 CVE-2020-10498 CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request. Phpkb No fix yet Fix from $1,6002020-03-12 HIGH 8.8 CVE-2020-10478 CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code … Phpkb No fix yet Fix from $1,9502020-03-12 CRITICAL 9.8 CVE-2020-10181 KEVEPSS 15% goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) … Enhanced Multimedia Router Firmware Mitigation only Fix from $2,3002020-03-11 HIGH 8.8 CVE-2020-9454 A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site admi… Registrationmagic after 4.6.0.3 Fix from $1,9502020-03-06 HIGH 8.8 CVE-2019-17642 An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharac… Centreon 18.10.8 / 19.04.2+ Fix from $1,9502020-03-05 HIGH 8.8 CVE-2020-10057 GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2… Genixcms No fix yet Fix from $1,9502020-03-04 HIGH 7.1 CVE-2020-3148 A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross… Prime Network Registrar 10.1+ Fix from $1,9502020-03-04 HIGH 8.8 CVE-2020-7988 An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privil… Phpipam No fix yet Fix from $1,9502020-03-04 HIGH 8.8 CVE-2019-20487 An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unau… Wnr1000 Firmware Mitigation only Fix from $1,9502020-03-02 HIGH 8.8 CVE-2015-1583 Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for re… Atutor Patch available Fix from $1,9502020-03-02 HIGH 8.8 CVE-2020-5402 In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback func… Cf Deployment 12.33.0 / 74.14.0+ Fix from $1,9502020-02-27 HIGH 8.8 CVE-2015-5686 Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would all… Puppet Enterprise 2015.2.0+ Fix from $1,9502020-02-27 MEDIUM 6.5 CVE-2019-19987 An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any HTML form. An … Visual Access Manager after 4.29.0 Fix from $1,6002020-02-26 HIGH 8.8 CVE-2020-9394 An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF. Pricing Table By Supsystic 1.8.2+ Fix from $1,9502020-02-25 MEDIUM 5.3 CVE-2020-9018 LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user. Litecart after 2.2.1 Fix from $1,6002020-02-25 HIGH 8.8 CVE-2019-20480 In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbi… Xgw 3000 Zigbee Gateway Firmware 2.4.0+ Fix from $1,9502020-02-24 HIGH 8.8 CVE-2020-9341 CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI. Candidats No fix yet Fix from $1,9502020-02-22 HIGH 8.8 CVE-2012-2629 Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack… Axous after 1.1.1 Fix from $1,9502020-02-20