Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2015-9394 The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. Users Ultra Membership 1.5.63+ Fix from $1,9502019-09-20 MEDIUM 6.5 CVE-2016-10997 The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php. Beauty Premium No fix yet Fix from $1,6002019-09-20 MEDIUM 6.5 CVE-2015-9387 The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF. Mtouch Quiz 3.1.3+ Fix from $1,6002019-09-20 MEDIUM 6.5 CVE-2015-9388 The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS. Mtouch Quiz 3.1.3+ Fix from $1,6002019-09-20 HIGH 8.8 CVE-2019-15089 An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator. Adas Mitigation only Fix from $1,9502019-09-20 HIGH 8.8 CVE-2019-16531 LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php. Layerbb 1.1.4+ Fix from $1,9502019-09-20 HIGH 8.8 CVE-2016-10989 The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF. Leenk.me 2.6.0+ Fix from $1,9502019-09-17 HIGH 8.8 CVE-2016-10974 The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS. Fluid Responsive Slideshow 2.2.7+ Fix from $1,9502019-09-17 HIGH 8.8 CVE-2016-10978 The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF. Tag Miner after 1.1.2 Fix from $1,9502019-09-17 HIGH 8.8 CVE-2016-10982 The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF. Kento Post View Counter after 2.8 Fix from $1,9502019-09-17 MEDIUM 6.5 CVE-2016-10962 The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter. Icegram Engage 1.9.19+ Fix from $1,6002019-09-16 HIGH 8.8 CVE-2019-16311 NIUSHOP V1.11 has CSRF via search_info to index.php. Niushop No fix yet Fix from $1,9502019-09-14 MEDIUM 6.5 CVE-2019-12922EPSS 10% A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. Fedora after 4.9.0.1 Fix from $1,6002019-09-13 CRITICAL 9.6 CVE-2019-13363 admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_de… Piwigo No fix yet Fix from $2,3002019-09-13 CRITICAL 9.6 CVE-2019-13364 admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is e… Piwigo No fix yet Fix from $2,3002019-09-13 HIGH 8.8 CVE-2016-10946 The wp-d3 plugin before 2.4.1 for WordPress has CSRF. Wp D3 2.4.1+ Fix from $1,9502019-09-13 HIGH 8.8 CVE-2016-10944 The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF. Multisite Post Duplicator 1.1.3+ Fix from $1,9502019-09-13 HIGH 8.8 CVE-2016-10945 The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF. Pagelines after 1.1.4 Fix from $1,9502019-09-13 MEDIUM 6.5 CVE-2016-10938 The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location. Copy Me No fix yet Fix from $1,6002019-09-13 HIGH 8.8 CVE-2019-5986 Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AN… Pr S300ne Firmware after 19.41 Fix from $1,9502019-09-12 HIGH 8.8 CVE-2019-5992 Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the… Wordpress Ultra Simple Paypal Shopping Cart after 4.4 Fix from $1,9502019-09-12 HIGH 8.8 CVE-2019-5993 Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack… Category Specific Rss Feed Subscription after 2.0 Fix from $1,9502019-09-12 HIGH 8.8 CVE-2019-1259 A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site reques… Sharepoint Foundation Patch available Fix from $1,9502019-09-11 HIGH 8.8 CVE-2019-1261 A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site reques… Sharepoint Enterprise Server Patch available Fix from $1,9502019-09-11 MEDIUM 6.5 CVE-2019-14998 The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its pro… Jira Server 8.4.0+ Fix from $1,6002019-09-11 HIGH 8.8 CVE-2017-18607 The avada theme before 5.1.5 for WordPress has CSRF. Avada 5.1.5+ Fix from $1,9502019-09-10 MEDIUM 6.5 CVE-2019-10253 A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malic… Teammate\+ No fix yet Fix from $1,6002019-09-09 HIGH 8.8 CVE-2019-16099 Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file. Unity Edgeconnect Sd Wan Firmware No fix yet Fix from $1,9502019-09-08 MEDIUM 6.5 CVE-2019-15128 iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user. If.svnadmin after 1.6.2 Fix from $1,6002019-09-06 HIGH 8.8 CVE-2019-16059 Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/… Sentrifugo No fix yet Fix from $1,9502019-09-06