Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2020-2090 A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL wit… Amazon Ec2 after 1.47 Fix from $1,9502020-01-15 HIGH 8.8 CVE-2020-2093 A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed… Health Advisor By Cloudbees after 3.0 Fix from $1,9502020-01-15 MEDIUM 6.5 CVE-2020-5502 phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships. Phpbb Mitigation only Fix from $1,6002020-01-15 HIGH 8.8 CVE-2011-2934 A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmat… Websitebaker after 2.8.1 Fix from $1,9502020-01-14 MEDIUM 6.5 CVE-2014-9382 Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation Freebox Os No fix yet Fix from $1,6002020-01-13 HIGH 8.8 CVE-2019-14304 Ricoh SP C250DN 1.06 devices allow CSRF. Sp C250sf Firmware 1.02 / 1.09+ Fix from $1,9502020-01-10 MEDIUM 6.5 CVE-2019-20178 Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user. Peel Shopping Mitigation only Fix from $1,6002020-01-09 HIGH 8.1 CVE-2019-6319 HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or h… Deskjet 3630 F5s43a Firmware Mitigation only Fix from $1,9502020-01-09 HIGH 8.1 CVE-2019-6320 Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN191… Deskjet 3630 F5s43a Firmware Mitigation only Fix from $1,9502020-01-09 HIGH 8.8 CVE-2020-6167 A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, mod… Minimal Coming Soon \& Maintenance Mode after 2.10 Fix from $1,9502020-01-09 MEDIUM 6.5 CVE-2011-5250 Snare for Linux before 1.7.0 has CSRF in the web interface. Snare 1.7.0+ Fix from $1,6002020-01-08 MEDIUM 6.5 CVE-2014-5516 Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to h… Konakart 7.3.0.0+ Fix from $1,6002020-01-03 MEDIUM 6.5 CVE-2014-3590 Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log … Satellite Mitigation only Fix from $1,6002020-01-02 HIGH 8.8 CVE-2013-3935 Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authen… Opsview 4.4.1 / 20130522+ Fix from $1,9502020-01-02 MEDIUM 6.5 CVE-2015-5595 Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin u… Zenphoto 1.4.9+ Fix from $1,6002019-12-31 MEDIUM 6.5 CVE-2019-12273 OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted b… Outsystems after 11 Fix from $1,6002019-12-31 MEDIUM 6.5 CVE-2013-0196 A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection me… Openshift No fix yet Fix from $1,6002019-12-30 HIGH 8.8 CVE-2019-19737 MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and … Yetishare after 4.5.3 Fix from $1,9502019-12-30 MEDIUM 6.5 CVE-2019-20071 On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs. Dl4343 Firmware No fix yet Fix from $1,6002019-12-30 HIGH 8.8 CVE-2014-3136 Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authen… Dwr 113 Firmware 2.03b02+ Fix from $1,9502019-12-27 MEDIUM 6.5 CVE-2013-4665 SPBAS Business Automation Software 2012 has CSRF. Business Automation Software No fix yet Fix from $1,6002019-12-27 HIGH 8.8 CVE-2019-16326 D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-20… Dir 601 Firmware No fix yet Fix from $1,9502019-12-26 HIGH 8.8 CVE-2019-19995 A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/user. Iwr 3000n Firmware Mitigation only Fix from $1,9502019-12-26 HIGH 8.8 CVE-2019-6027 Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack the authentication of administr… Wpspellcheck after 7.1.9 Fix from $1,9502019-12-26 HIGH 8.8 CVE-2019-6030 Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack the authentication of admini… Custom Body Class after 0.6.0 Fix from $1,9502019-12-26 HIGH 8.8 CVE-2019-19979 A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious co… Wp Maintenance 5.0.6+ Fix from $1,9502019-12-26 MEDIUM 5.4 CVE-2019-19981 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings. Email Subscribers \& Newsletters 4.2.3+ Fix from $1,6002019-12-26 HIGH 8.8 CVE-2018-1934 IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz… Cognos Business Intelligence Mitigation only Fix from $1,9502019-12-20 CRITICAL 9.0 CVE-2019-19915 The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or i… 301 Redirects 2.45+ Fix from $2,3002019-12-19 HIGH 8.8 CVE-2019-17633 For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitr… Che after 7.3.0 Fix from $1,9502019-12-19