Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2019-11569 Veeam ONE Reporter 9.5.0.3201 allows CSRF. One Reporter No fix yet Fix from $1,9502019-05-06 HIGH 8.8 CVE-2018-4066 An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially… Airlink Es450 Firmware No fix yet Fix from $1,9502019-05-06 HIGH 8.8 CVE-2019-5430 In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration … Unifi Video after 3.10.0 Fix from $1,9502019-05-06 MEDIUM 5.4 CVE-2019-5431 This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verificati… Twitter Kit after 3.4.0 Fix from $1,6002019-05-06 HIGH 8.8 CVE-2019-1857 A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross… Hx220c M5 Firmware Mitigation only Fix from $1,9502019-05-03 HIGH 8.8 CVE-2019-1713 A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote atta… Adaptive Security Appliance Software 9.4.4.34 / 9.6.4.25+ Fix from $1,9502019-05-03 HIGH 8.8 CVE-2019-11617 doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "… Doorgets Cms No fix yet Fix from $1,9502019-04-30 MEDIUM 6.1 CVE-2019-11193 The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass … Directadmin after 1.561 Fix from $1,6002019-04-30 HIGH 8.8 CVE-2018-14930 An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebApp/gcmsRefInsert?name=SUPP UR… Intellect Core Banking No fix yet Fix from $1,9502019-04-30 HIGH 8.8 CVE-2018-15206 BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf. Smartvista No fix yet Fix from $1,9502019-04-30 MEDIUM 6.5 CVE-2019-10307 A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave f… Static Analysis Utilities after 1.95 Fix from $1,6002019-04-30 HIGH 8.8 CVE-2019-10310 A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doT… Ansible Tower after 0.9.1 Fix from $1,9502019-04-30 HIGH 8.8 CVE-2019-10315 Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF. Github Authentication after 0.31 Fix from $1,9502019-04-30 HIGH 8.8 CVE-2018-5123 A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in al… Bugzilla 4.4+ Fix from $1,9502019-04-29 HIGH 8.8 CVE-2019-11590 The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclu… Form Maker 1.13.5+ Fix from $1,9502019-04-29 HIGH 8.8 CVE-2019-11591 The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file… Contact Form 1.13.5+ Fix from $1,9502019-04-29 HIGH 8.8 CVE-2019-11557 The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant lo… Wp Form Builder 1.0.69+ Fix from $1,9502019-04-26 HIGH 8.8 CVE-2015-9284 The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails fra… Omniauth 2.0.0+ Fix from $1,9502019-04-26 HIGH 8.8 CVE-2019-8991 The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO A… Activematrix Bpm after 4.2.0 Fix from $1,9502019-04-24 MEDIUM 6.1 CVE-2019-11203 The workspace client, openspace client, app development client, and REST API of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM … Activematrix Business Process Management after 4.2.0 Fix from $1,6002019-04-24 HIGH 8.8 CVE-2019-11456 Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code. Gila Cms No fix yet Fix from $1,9502019-04-22 HIGH 8.8 CVE-2019-11416 A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user. Iwr 3000n Firmware No fix yet Fix from $1,9502019-04-22 HIGH 8.8 CVE-2019-11374EPSS 10% 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. 74cms No fix yet Fix from $1,9502019-04-20 MEDIUM 6.5 CVE-2019-11375 Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI. Msvod No fix yet Fix from $1,6002019-04-20 HIGH 8.8 CVE-2019-3718 Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could po… Supportassist 3.2.0.90+ Fix from $1,9502019-04-18 MEDIUM 6.5 CVE-2018-17168 PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page. For example, an administra… Printeron No fix yet Fix from $1,6002019-04-18 HIGH 8.0 CVE-2019-10300 A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation… GitLab after 1.5.11 Fix from $1,9502019-04-18 MEDIUM 6.5 CVE-2019-10304 A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method … Xebialabs Xl Deploy after 7.5.3 Fix from $1,6002019-04-18 MEDIUM 6.5 CVE-2019-1722 A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticat… Expressway Series Mitigation only Fix from $1,6002019-04-18 HIGH 8.8 CVE-2019-1797 A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker… Wireless Lan Controller Software 8.3.150.0 / 8.5.150.0+ Fix from $1,9502019-04-18