Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2019-10464 A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-… Deploy Weblogic after 4.1 Fix from $1,9502019-10-23 HIGH 8.8 CVE-2019-10468 A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified… Kubernetes Ci after 1.3 Fix from $1,9502019-10-23 HIGH 8.8 CVE-2015-9497 The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php. Ad Inserter 1.5.3+ Fix from $1,9502019-10-22 HIGH 8.8 CVE-2015-9498 The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value. Wps Hide Login 1.1+ Fix from $1,9502019-10-22 HIGH 8.8 CVE-2019-17367 OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/for… Openwrt Patch available Fix from $1,9502019-10-18 HIGH 8.8 CVE-2019-17118 A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended ac… 2fa Enterprise Server Patch available Fix from $1,9502019-10-17 HIGH 8.8 CVE-2019-17675 WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. WordPress 5.2.4+ Fix from $1,9502019-10-17 HIGH 8.8 CVE-2019-17676 app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, a… Metinfo No fix yet Fix from $1,9502019-10-17 HIGH 8.8 CVE-2019-12636 A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attac… Sf250 24 Firmware 2.5.0.90+ Fix from $1,9502019-10-16 HIGH 8.8 CVE-2019-10437 A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attack… Crx Content Package Deployer after 1.8.1 Fix from $1,9502019-10-16 MEDIUM 6.5 CVE-2016-11015 NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter. Jnr1010 Firmware 1.0.0.32+ Fix from $1,6002019-10-16 CRITICAL 9.8 CVE-2019-17600 Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled. Iwr 1000n Firmware No fix yet Fix from $2,3002019-10-15 HIGH 8.8 CVE-2019-17593 JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator. Jizhicms No fix yet Fix from $1,9502019-10-14 MEDIUM 6.5 CVE-2019-17521 An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI, Landing Cms No fix yet Fix from $1,6002019-10-12 HIGH 8.8 CVE-2018-20582 The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery. Gree\+ No fix yet Fix from $1,9502019-10-11 CRITICAL 9.8 CVE-2019-17495EPSS 6% A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) techniq… Swagger Ui 3.23.11+ Fix from $2,3002019-10-10 HIGH 8.8 CVE-2019-17386 The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php. Animate It\! 2.3.6+ Fix from $1,9502019-10-10 HIGH 8.8 CVE-2019-17431 An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability. Fastadmin No fix yet Fix from $1,9502019-10-10 MEDIUM 6.5 CVE-2019-17432 An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultan… Fastadmin No fix yet Fix from $1,6002019-10-10 HIGH 8.8 CVE-2019-13529 An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the… Sunny Webbox Firmware after 1.6 Fix from $1,9502019-10-09 MEDIUM 6.5 CVE-2019-17369 OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superad… Otcms No fix yet Fix from $1,6002019-10-09 HIGH 8.1 CVE-2015-9455 The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photo… Buddypress Activity Plus 1.6.2+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17217 An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web… Combi Stream Mslq Firmware Mitigation only Fix from $1,9502019-10-06 HIGH 8.8 CVE-2019-15040 JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page. Youtrack 2019.1+ Fix from $1,9502019-10-02 MEDIUM 6.5 CVE-2019-1915 A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (… Unified Communications Manager Mitigation only Fix from $1,6002019-10-02 HIGH 8.8 CVE-2019-16993 In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Pa… Debian Linux after 3.1.7 Fix from $1,9502019-09-30 MEDIUM 6.5 CVE-2019-13376 phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token… Phpbb No fix yet Fix from $1,6002019-09-27 HIGH 8.8 CVE-2019-16667EPSS 55% diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs b… Pfsense No fix yet Fix from $1,9502019-09-26 HIGH 8.8 CVE-2015-9445 The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation. Unite Gallery Lite 1.5+ Fix from $1,9502019-09-26 MEDIUM 6.5 CVE-2015-9447 The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters. Unite Gallery Lite 1.5+ Fix from $1,6002019-09-26