Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2019-6325 HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) ma… T6b80a Firmware 2019-04-19 / 2019-04-26+ Fix from $1,9502019-06-17 MEDIUM 6.5 CVE-2019-0996 A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site reque… Azure Devops Server Patch available Fix from $1,6002019-06-12 HIGH 8.8 CVE-2019-3410 All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems fr… Wf820\+ Lte Outdoor Cpe Firmware 1.0.0b06+ Fix from $1,9502019-06-11 HIGH 8.8 CVE-2019-10338 A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed at… Jx Resources after 1.0.36 Fix from $1,9502019-06-11 MEDIUM 6.5 CVE-2019-11517 WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An att… Wampserver 3.1.9+ Fix from $1,6002019-06-10 HIGH 8.8 CVE-2018-10696 An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, t… Awk 3121 Firmware No fix yet Fix from $1,9502019-06-07 HIGH 8.8 CVE-2019-1881 A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to c… Industrial Network Director Mitigation only Fix from $1,9502019-06-05 MEDIUM 6.5 CVE-2019-12616EPSS 19% An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin u… phpMyAdmin 4.9.0+ Fix from $1,6002019-06-05 HIGH 8.8 CVE-2019-9882 Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user… Msr35 Isherlock Base 1.5.127 / 1.5.196+ Fix from $1,9502019-06-03 HIGH 8.8 CVE-2019-9883 Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin… Msr35 Isherlock Base 1.5.127 / 1.5.196+ Fix from $1,9502019-06-03 MEDIUM 6.5 CVE-2019-10324 A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStagin… Artifactory after 3.2.2 Fix from $1,6002019-05-31 HIGH 8.8 CVE-2019-12502 There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account via the /admin/access URI. S14 Firmware No fix yet Fix from $1,9502019-05-31 HIGH 8.8 CVE-2018-16218 A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote … Ultra Elegant Ip Phone Sip T41p Firmware No fix yet Fix from $1,9502019-05-29 MEDIUM 6.1 CVE-2019-12361 EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. Th… Empirecms No fix yet Fix from $1,6002019-05-27 HIGH 8.8 CVE-2016-10756 Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files… Kliqqi Cms No fix yet Fix from $1,9502019-05-24 HIGH 8.8 CVE-2016-10757 In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/… Readaxo No fix yet Fix from $1,9502019-05-24 MEDIUM 6.5 CVE-2018-19613 Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF. Dr 260 Firmware No fix yet Fix from $1,6002019-05-24 HIGH 8.8 CVE-2019-10847 Computrols CBAS 18.0.0 allows Cross-Site Request Forgery. Computrols Building Automation Software after 19.0.0 Fix from $1,9502019-05-24 HIGH 8.8 CVE-2018-7828 A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenti… D6220 Firmware 2.2.3.0+ Fix from $1,9502019-05-22 MEDIUM 6.5 CVE-2019-12253 my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting. My Little Forum 2.4.20+ Fix from $1,6002019-05-21 HIGH 7.2 CVE-2019-12239 The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require ad… Wp Booking System 1.5.2+ Fix from $1,9502019-05-20 HIGH 8.8 CVE-2018-16136 An issue was discovered in the administrator interface in IPBRICK OS 6.3. The application doesn't check for Anti-CSRF tokens, allowing the submission… Ipbrick Os No fix yet Fix from $1,9502019-05-13 MEDIUM 6.5 CVE-2018-14711 Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing acti… Rt Ac3200 Firmware No fix yet Fix from $1,6002019-05-13 HIGH 8.8 CVE-2019-11886 The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as… Visual Css Style Editor 7.2.1+ Fix from $1,9502019-05-13 HIGH 8.8 CVE-2018-1790 IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an atta… Financial Transaction Manager after 3.0.2.1 Fix from $1,9502019-05-10 HIGH 8.8 CVE-2017-12789 Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/o… Metinfo No fix yet Fix from $1,9502019-05-10 MEDIUM 6.5 CVE-2017-12790 Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. … Metinfo No fix yet Fix from $1,6002019-05-09 HIGH 8.1 CVE-2019-7746 JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and… Jmr1140 Firmware No fix yet Fix from $1,9502019-05-07 HIGH 8.8 CVE-2018-2001 IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execut… Curam Social Program Management after 7.0.4.0 Fix from $1,9502019-05-07 HIGH 8.8 CVE-2018-13993 The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF. Fl Switch 3005 Firmware after 1.34 Fix from $1,9502019-05-07