Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.1 CVE-2019-14526 An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a d… Mr1100 Firmware 12.06.03+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2019-10199 It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw t… Keycloak after 6.0.1 Fix from $1,9502019-08-14 HIGH 8.8 CVE-2017-18510 The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions. Custom Sidebars 3.1.0+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2017-18511 The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF. Custom Sidebars 3.0.8.1+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2017-18512 The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF. Newsletter By Supsystic 1.1.8+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2017-18513 The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface. Responsive Menu 3.1.4+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2018-20967 The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv 5.6.1+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2018-20968 The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF. Ultimate Exporter 1.4.2+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2013-7476 The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface. Simple Fields 1.2+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2015-9307 The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. Wp Maps 2.3.10+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2015-9308 The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. Wp Maps 2.3.10+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2015-9309 The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature. Wp Maps 2.3.10+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2016-10882 The google-document-embedder plugin before 2.6.2 for WordPress has CSRF. Google Doc Embedder 2.6.2+ Fix from $1,9502019-08-14 MEDIUM 6.5 CVE-2016-10883 The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users. Simple Add Pages Or Posts 1.7+ Fix from $1,6002019-08-14 HIGH 8.8 CVE-2016-10884 The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues. Simple Membership 3.3.3+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2016-10885 The wp-editor plugin before 1.2.6 for WordPress has CSRF. Wp Editor 1.2.6+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2019-11207 The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contain… Loglogic Enterprise Virtual Appliance after 6.2.1 Fix from $1,9502019-08-13 HIGH 8.8 CVE-2018-20964 The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. Contact Form Email 1.2.66+ Fix from $1,9502019-08-13 HIGH 8.8 CVE-2017-18504 The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF. Twitter Cards Meta 2.5.0+ Fix from $1,9502019-08-12 HIGH 8.8 CVE-2016-10874 The wp-database-backup plugin before 4.3.3 for WordPress has CSRF. Wp Database Backup 4.3.3+ Fix from $1,9502019-08-12 HIGH 8.8 CVE-2016-10876 The wp-database-backup plugin before 4.3.1 for WordPress has CSRF. Wp Database Backup 4.3.1+ Fix from $1,9502019-08-12 HIGH 8.8 CVE-2019-14933 Bagisto 0.1.5 allows CSRF under /admin URIs. Bagisto No fix yet Fix from $1,9502019-08-11 MEDIUM 6.1 CVE-2016-10865 The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demo… Lightbox Plus Colorbox after 2.7.2 Fix from $1,6002019-08-09 HIGH 8.8 CVE-2016-10862 Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page. Airstream Nas Firmware No fix yet Fix from $1,9502019-08-08 HIGH 8.8 CVE-2016-10863 Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure. Ew 7438rpn Mini Firmware No fix yet Fix from $1,9502019-08-08 MEDIUM 5.4 CVE-2017-18485 Cognitoys Dino devices allow profiles_add.html CSRF. Cognitoys Dino Firmware No fix yet Fix from $1,6002019-08-08 HIGH 8.8 CVE-2015-9292 6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter). 6kbbs No fix yet Fix from $1,9502019-08-08 MEDIUM 5.7 CVE-2019-14683 The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSR… Import Users From Csv With Meta 1.14.2.2+ Fix from $1,6002019-08-08 MEDIUM 6.5 CVE-2019-14679 core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF. Arprice Lite No fix yet Fix from $1,6002019-08-08 MEDIUM 5.7 CVE-2019-14680 The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php … Admin Renamer Extended No fix yet Fix from $1,6002019-08-08