Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2019-20401 Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished bei… Jira Server 8.5.2 / 8.6.0+ Fix from $1,6002020-02-06 HIGH 8.8 CVE-2020-8658EPSS 10% The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_… Htaccess after 1.8.1 Fix from $1,9502020-02-06 HIGH 8.8 CVE-2011-0525 Batavi before 1.0 has CSRF. Batavi 1.0+ Fix from $1,9502020-02-05 HIGH 8.8 CVE-2019-4613 IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr… Planning Analytics Mitigation only Fix from $1,9502020-02-05 MEDIUM 6.5 CVE-2020-8615EPSS 9% A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performin… Tutor Lms 1.5.3+ Fix from $1,6002020-02-04 CRITICAL 9.6 CVE-2019-10784 phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area… Phppgadmin after 7.12.1 Fix from $2,3002020-02-04 HIGH 8.8 CVE-2013-7053 D-Link DIR-100 4.03B07: cli.cgi CSRF Dir 100 Firmware No fix yet Fix from $1,9502020-02-04 MEDIUM 6.5 CVE-2020-8504 School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user. School Management Software Php\/mysql after 2019-03-14 Fix from $1,6002020-01-31 MEDIUM 6.5 CVE-2020-8505 School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user. School Management Software Php\/mysql after 2019-03-14 Fix from $1,6002020-01-31 MEDIUM 6.5 CVE-2019-7654 Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be trick… Streaming Engine after 4.8.0 Fix from $1,6002020-01-29 HIGH 8.8 CVE-2020-7965 flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request … Webargs after 5.5.2 Fix from $1,9502020-01-29 HIGH 8.8 CVE-2020-8424 Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php. Cups Easy No fix yet Fix from $1,9502020-01-28 MEDIUM 6.5 CVE-2020-8425 Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php. Cups Easy \(purchase \& Inventory\) No fix yet Fix from $1,6002020-01-28 HIGH 8.8 CVE-2020-8420 An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability. Joomla\! 3.9.15+ Fix from $1,9502020-01-28 HIGH 8.8 CVE-2013-3093 ASUS RT-N56U devices allow CSRF. Rt N56u Firmware Mitigation only Fix from $1,9502020-01-28 HIGH 8.8 CVE-2020-8417EPSS 12% The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu. Code Snippets 2.14.0+ Fix from $1,9502020-01-28 HIGH 8.8 CVE-2020-8419 An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities. Joomla\! 3.9.15+ Fix from $1,9502020-01-28 HIGH 8.8 CVE-2015-5483 Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authen… Private Only No fix yet Fix from $1,9502020-01-28 MEDIUM 6.5 CVE-2013-4865 Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack t… Veralite Firmware No fix yet Fix from $1,6002020-01-28 HIGH 8.8 CVE-2020-7991 Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. Framework No fix yet Fix from $1,9502020-01-26 MEDIUM 6.5 CVE-2014-2050 Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authent… Owncloud 5.0.15 / 6.0.2+ Fix from $1,6002020-01-23 HIGH 8.8 CVE-2019-16513 An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests. Control No fix yet Fix from $1,9502020-01-23 HIGH 8.8 CVE-2011-3612 Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12. Usebb 1.0.12+ Fix from $1,9502020-01-22 HIGH 8.8 CVE-2011-3582 A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive… Advanced Electron Forums after 1.0.9 Fix from $1,9502020-01-22 HIGH 8.8 CVE-2020-6849 The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS. Marketo Forms And Tracking after 1.0.2 Fix from $1,9502020-01-21 HIGH 8.8 CVE-2019-3864 A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which i… Quay 3.0.0+ Fix from $1,9502020-01-21 MEDIUM 5.3 CVE-2020-5397 Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc … Spring Framework 5.2.3+ Fix from $1,6002020-01-17 HIGH 8.8 CVE-2019-19854 An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens to mitigate against CSRF; it… Serpico Patch available Fix from $1,9502020-01-15 HIGH 8.8 CVE-2019-18271 OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced… Pi Vision 2019+ Fix from $1,9502020-01-15 HIGH 8.8 CVE-2020-2098 A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user a… Sounds after 0.5 Fix from $1,9502020-01-15