Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2019-10642 Contao 4.7 allows CSRF. Contao Cms Mitigation only Fix from $1,9502019-04-17 MEDIUM 6.5 CVE-2019-9176 An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows CSRF. GitLab 11.6.10 / 11.7.6+ Fix from $1,6002019-04-17 MEDIUM 6.5 CVE-2018-13810 A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web server of the affected CP dev… Cp 1604 Firmware after 2.8 Fix from $1,6002019-04-17 HIGH 8.8 CVE-2018-16966 There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. File Manager No fix yet Fix from $1,9502019-04-15 HIGH 8.8 CVE-2018-17584 The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page. Wp Fastest Cache No fix yet Fix from $1,9502019-04-15 HIGH 8.8 CVE-2017-18366 Subrion CMS 4.1.5 has CSRF in blog/delete/. Subrion Cms No fix yet Fix from $1,9502019-04-15 HIGH 8.8 CVE-2019-11077 FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI. Fastadmin No fix yet Fix from $1,9502019-04-11 HIGH 8.8 CVE-2019-11078 MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI. Mkcms No fix yet Fix from $1,9502019-04-11 HIGH 8.8 CVE-2019-0229 A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site reques… Airflow after 1.10.2 Fix from $1,9502019-04-10 HIGH 8.8 CVE-2018-2000 IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious… Business Automation Workflow Patch available Fix from $1,9502019-04-08 HIGH 8.8 CVE-2019-10888 A CSRF Issue that can add an admin user was discovered in UKcms v1.1.10 via admin.php/admin/role/add.html. Ukcms No fix yet Fix from $1,9502019-04-05 MEDIUM 6.1 CVE-2018-20816 An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka… Suitecrm 7.8.24 / 7.10.11+ Fix from $1,6002019-04-05 HIGH 8.8 CVE-2019-10874 Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploa… Bolt Patch available Fix from $1,9502019-04-05 MEDIUM 6.5 CVE-2019-10292 A cross-site request forgery vulnerability in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers to in… Kmap Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003098 A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method al… Openid Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-10278 A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method a… Jenkins Reviewbot Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-10289 A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI … Netsparker Cloud Scan after 1.1.5 Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003076 A cross-site request forgery vulnerability in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form valida… Audit To Database Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003078 A cross-site request forgery vulnerability in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validat… Vmware Lab Manager Slaves Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003080 A cross-site request forgery vulnerability in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin for… Openshift Deployer after 1.2.0 Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003082 A cross-site request forgery vulnerability in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attack… Gearman Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003084 A cross-site request forgery vulnerability in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation … Zephyr Enterprise Test Management Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003086 A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form valida… Chef Sinatra Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003090 A cross-site request forgery vulnerability in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method… Soasta Cloudtest Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003092 A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows at… Nomad Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003058 A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to… Ftp Publisher Mitigation only Fix from $1,6002019-04-04 HIGH 8.8 CVE-2019-10673 A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become adm… Ultimate Member 2.0.40+ Fix from $1,9502019-04-03 HIGH 8.8 CVE-2018-1622 IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute… Security Privileged Identity Manager Mitigation only Fix from $1,9502019-04-02 MEDIUM 6.3 CVE-2019-3876 A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X… Openshift Container Platform after 3.11 Fix from $1,6002019-04-01 HIGH 8.8 CVE-2014-7198 OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection. Omero 5.0.6+ Fix from $1,9502019-04-01