Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2019-19832 Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserNam… Altalink C8035 Firmware No fix yet Fix from $1,9502019-12-18 MEDIUM 6.5 CVE-2019-19833EPSS 15% In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in appl… Tautulli No fix yet Fix from $1,6002019-12-18 HIGH 8.8 CVE-2019-11657 Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could… Arcsight Logger 7.0+ Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-16575 A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-sp… Alauda Kubernetes Support after 2.3.0 Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-16573 A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers to connect to an attacker-spec… Alauda Devops Pipeline after 2.3.2 Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-16570 A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web ser… Rapiddeploy after 4.1 Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-16565 A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL … Team Concert after 1.3.0 Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-16560 A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and de… Websphere Deployer after 1.6.1 Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-16553 A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers to have Jenkins evaluate a co… Build Failure Analyzer after 1.24.1 Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-16550 A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to ha… Maven after 0.16.1 Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-16551 A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified H… Gerrit Trigger after 2.30.1 Fix from $1,9502019-12-17 MEDIUM 6.5 CVE-2017-18107 Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users… Crowd 3.1.1+ Fix from $1,6002019-12-17 HIGH 8.8 CVE-2014-0197 CFME: CSRF protection vulnerability via permissive check of the referrer header Cloudforms after 5.9.3.1 Fix from $1,9502019-12-13 HIGH 8.1 CVE-2019-13930 A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an … Xhq 6.0.0.2+ Fix from $1,9502019-12-12 HIGH 8.8 CVE-2019-15934 Intesync Solismed 3.3sp has CSRF. Solismed No fix yet Fix from $1,9502019-12-12 HIGH 8.8 CVE-2019-0398 Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, m… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502019-12-11 MEDIUM 6.5 CVE-2014-0026 katello-headpin is vulnerable to CSRF in REST API Subscription Asset Manager No fix yet Fix from $1,6002019-12-11 HIGH 8.8 CVE-2019-19685 RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions. Nopcommerce No fix yet Fix from $1,9502019-12-09 HIGH 8.8 CVE-2019-18346 A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary… Davical after 1.1.8 Fix from $1,9502019-12-04 MEDIUM 6.5 CVE-2019-19516EPSS 10% Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password. Wrn 150 Firmware No fix yet Fix from $1,6002019-12-02 HIGH 8.8 CVE-2019-19469 In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with s… Amanda Mitigation only Fix from $1,9502019-12-01 MEDIUM 5.3 CVE-2019-19375 In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribu… Octopus Deploy 2019.6.14 / 2019.9.8+ Fix from $1,6002019-11-28 HIGH 8.8 CVE-2019-17590 The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the c… Csrf Magic after 2016-03-27 Fix from $1,9502019-11-26 MEDIUM 6.1 CVE-2019-18677EPSS 7% An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly inte… Ubuntu Linux after 4.8 Fix from $1,6002019-11-26 MEDIUM 6.5 CVE-2019-16002 A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-… Sd Wan Firmware 19.2.0+ Fix from $1,6002019-11-26 MEDIUM 6.5 CVE-2011-3609 A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for … Jboss Application Server Mitigation only Fix from $1,6002019-11-26 HIGH 8.8 CVE-2013-6811 Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authenticat… Dsl6740u Firmware Mitigation only Fix from $1,9502019-11-22 HIGH 8.8 CVE-2019-19013 A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request. Pagekit No fix yet Fix from $1,9502019-11-22 HIGH 8.8 CVE-2012-2079 A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal. Activity Mitigation only Fix from $1,9502019-11-22 HIGH 8.8 CVE-2015-3140 Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, … Synaman Mitigation only Fix from $1,9502019-11-21