Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2019-5963 Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrat… Salesiq after 1.0.8 Fix from $1,9502019-07-05 HIGH 8.4 CVE-2019-6636 On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability… Big Ip Advanced Firewall Manager 12.1.4.1 / 13.1.1.5+ Fix from $1,9502019-07-03 HIGH 8.8 CVE-2019-12851 A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852. Youtrack 2018.4.49852+ Fix from $1,9502019-07-03 HIGH 8.8 CVE-2019-5630 A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue al… Nexpose after 6.5.68 Fix from $1,9502019-07-03 HIGH 8.8 CVE-2018-10986 OX Guard 2.8.0 has CSRF. Ox Guard Mitigation only Fix from $1,9502019-07-03 HIGH 8.8 CVE-2018-11427 CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to per… Oncell G3150 Hspa Firmware after 1.4 Fix from $1,9502019-07-03 HIGH 8.8 CVE-2017-8406 An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. … Dcs 1130 Firmware No fix yet Fix from $1,9502019-07-02 HIGH 8.8 CVE-2017-8407 An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the we… Dcs 1130 Firmware No fix yet Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-7262EPSS 16% Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF). Linear Emerge Essential Firmware after 1.00-06 Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-7270 Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF). Linear Emerge 50p Firmware after 4.6.07 Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-13056 An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of t… Cyberpanel after 1.8.4 Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-7273 Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF). Enterprise after 2.3.0a Fix from $1,9502019-07-01 HIGH 8.8 CVE-2019-7281 Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform … Flexair after 2.3.38 Fix from $1,9502019-07-01 HIGH 8.8 CVE-2019-12826 A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote a… Widget Logic 5.10.2+ Fix from $1,9502019-07-01 HIGH 8.8 CVE-2018-20848 Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleu… Peel Shopping No fix yet Fix from $1,9502019-06-30 MEDIUM 6.5 CVE-2019-5814 Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HT… Chrome 74.0.3729.108+ Fix from $1,6002019-06-27 HIGH 8.8 CVE-2019-6166 A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery. Service Bridge 4.1.0.1+ Fix from $1,9502019-06-26 HIGH 8.8 CVE-2018-1858 IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz… Api Connect after 5.0.8.6 Fix from $1,9502019-06-25 HIGH 8.8 CVE-2019-9958 CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin acc… Espressreport Enterprise Server No fix yet Fix from $1,9502019-06-24 HIGH 8.8 CVE-2019-12836 The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to … Jeditor 3.0.6+ Fix from $1,9502019-06-21 HIGH 8.8 CVE-2019-1904 A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request… Ios Xe Mitigation only Fix from $1,9502019-06-21 HIGH 8.8 CVE-2019-1874 A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to cond… Prime Service Catalog Patch available Fix from $1,9502019-06-20 HIGH 8.0 CVE-2019-1632 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker t… Integrated Management Controller Mitigation only Fix from $1,9502019-06-20 HIGH 8.8 CVE-2018-17387 CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account. Nimble Professional No fix yet Fix from $1,9502019-06-19 HIGH 8.8 CVE-2018-17389 CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account. Live Call Support No fix yet Fix from $1,9502019-06-19 HIGH 8.8 CVE-2017-8328 An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of… Almond 2015 Firmware No fix yet Fix from $1,9502019-06-18 HIGH 8.0 CVE-2017-8334 An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of… Almond 2015 Firmware No fix yet Fix from $1,9502019-06-18 HIGH 8.8 CVE-2018-18802 The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit. Welcome To Our Resort No fix yet Fix from $1,9502019-06-18 HIGH 8.8 CVE-2019-4142 IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u… Cloud Private after 2.1.0.3 Fix from $1,9502019-06-18 HIGH 8.8 CVE-2017-9381 An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a user with the capability of installing or deletin… Veraedge Firmware after 1.7.481 Fix from $1,9502019-06-17