Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2013-3312 Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of u… Nexus 543 Firmware No fix yet Fix from $1,9502019-11-21 HIGH 8.8 CVE-2019-16548 A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used … Google Compute Engine 4.2.0+ Fix from $1,9502019-11-21 HIGH 8.8 CVE-2011-4952 cobbler: Web interface lacks CSRF protection when using Django framework Cobbler Mitigation only Fix from $1,9502019-11-19 MEDIUM 6.5 CVE-2019-18651 A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious … Infinias Access Control Firmware after 6.6.9586.0 Fix from $1,6002019-11-14 HIGH 8.8 CVE-2013-3366 Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24M… Tew 812dru Firmware Mitigation only Fix from $1,9502019-11-13 HIGH 8.8 CVE-2019-18884 index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users. Rise Ultimate Project Manager No fix yet Fix from $1,9502019-11-13 MEDIUM 6.5 CVE-2013-3516 NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF toke… Wnr3500u Firmware No fix yet Fix from $1,6002019-11-13 MEDIUM 6.5 CVE-2012-4385 letodms 3.3.6 has CSRF via change password Debian Linux No fix yet Fix from $1,6002019-11-13 HIGH 8.8 CVE-2010-3305 Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password. Pixelpost No fix yet Fix from $1,9502019-11-12 HIGH 8.8 CVE-2019-17237 includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF. Igniteup after 3.4 Fix from $1,9502019-11-12 HIGH 8.8 CVE-2019-18411 Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability… Manageengine Adselfservice Plus Mitigation only Fix from $1,9502019-11-06 HIGH 8.8 CVE-2019-18650 An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability. Joomla\! after 3.9.12 Fix from $1,9502019-11-06 HIGH 8.0 CVE-2019-8109 A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft … Magento 2.2.10 / 2.3.2+ Fix from $1,9502019-11-05 MEDIUM 6.5 CVE-2013-6275 Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. Debian Linux after 5.1.2 Fix from $1,6002019-11-05 HIGH 8.8 CVE-2013-6364 Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book Debian Linux No fix yet Fix from $1,9502019-11-05 MEDIUM 5.3 CVE-2013-6365 Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions Debian Linux Patch available Fix from $1,6002019-11-05 MEDIUM 6.5 CVE-2019-13497 One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests. Cloud Access Manager 8.1.4+ Fix from $1,6002019-11-04 HIGH 8.8 CVE-2019-18206 A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload. Infobusiness after 4.4.1 Fix from $1,9502019-10-30 HIGH 8.8 CVE-2019-9926 An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptRepor… Labkey Server No fix yet Fix from $1,9502019-10-29 HIGH 8.8 CVE-2010-4241 Tiki Wiki CMS Groupware 5.2 has CSRF Tikiwiki Cms\/groupware No fix yet Fix from $1,9502019-10-28 HIGH 8.8 CVE-2013-4848 TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities. Tl Wdr4300 Firmware No fix yet Fix from $1,9502019-10-25 MEDIUM 6.5 CVE-2019-8234 Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive i… Experience Manager Mitigation only Fix from $1,6002019-10-25 HIGH 8.8 CVE-2019-12095 Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags para… Groupware after 5.2.22 Fix from $1,9502019-10-24 HIGH 8.8 CVE-2019-18414 Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF… Restaurant Management System No fix yet Fix from $1,9502019-10-24 MEDIUM 6.5 CVE-2019-9596 Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint. Enterprise Immune System 3.1+ Fix from $1,6002019-10-23 MEDIUM 6.5 CVE-2019-9597 Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint. Enterprise Immune System 3.1+ Fix from $1,6002019-10-23 HIGH 8.8 CVE-2019-18220 Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowi… Sitemagic Mitigation only Fix from $1,9502019-10-23 HIGH 8.8 CVE-2019-18280 Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead … Online Grading System No fix yet Fix from $1,9502019-10-23 HIGH 8.8 CVE-2019-10471 A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using att… Libvirt Slaves after 1.8.5 Fix from $1,9502019-10-23 HIGH 8.1 CVE-2019-10462 A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an at… Dynatrace Application Monitoring after 2.1.3 Fix from $1,9502019-10-23