Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
CRITICAL 9.8 CVE-2019-10655EPSS 15% Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unau… Gac2500 Firmware 1.0.3.51 / 1.0.3.219+ Fix from $2,3002019-03-30 HIGH 8.8 CVE-2019-10644 An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account. Hybbs No fix yet Fix from $1,9502019-03-30 HIGH 8.8 CVE-2019-9604 PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions. Online Lottery Php Readymade Script No fix yet Fix from $1,9502019-03-29 MEDIUM 6.8 CVE-2019-6607 On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross-site scripting vulnerability… Big Ip Application Security Manager after 14.0.0.2 Fix from $1,6002019-03-28 HIGH 7.1 CVE-2019-1003044 A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified… Slack Notification after 2.19 Fix from $1,9502019-03-28 MEDIUM 6.5 CVE-2019-1003046 A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection … Fortify On Demand Uploader after 3.0.10 Fix from $1,6002019-03-28 HIGH 8.8 CVE-2019-10237 S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related issue to… S Cms No fix yet Fix from $1,9502019-03-27 CRITICAL 10.0 CVE-2019-3809 A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, w… Moodle after 3.1.15 Fix from $2,3002019-03-25 HIGH 8.8 CVE-2019-1764 A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an una… Ip Phone 8821 Firmware 11.0 / 12.5+ Fix from $1,9502019-03-22 HIGH 8.8 CVE-2019-7433 PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature. Rental Bike Script No fix yet Fix from $1,9502019-03-21 MEDIUM 6.5 CVE-2019-7440 JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcm… Jiofi 4g M2s Firmware No fix yet Fix from $1,6002019-03-21 HIGH 8.8 CVE-2019-7391EPSS 14% ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF. Dsl 491hnu B10b Firmware No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2019-6967EPSS 13% AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF. Air 5341 Firmware No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2019-6282 ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wls… Gpn2.4p21 C Cn Firmware No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2018-20641 PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature. Entrepreneur Job Portal Script No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2018-20644 PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature. Basic B2b Script No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2018-20648 PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php. Car Rental Script No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2018-20633 PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature. Advance B2b Script No fix yet Fix from $1,9502019-03-21 MEDIUM 6.5 CVE-2018-19511 wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator password. Webgalamb No fix yet Fix from $1,6002019-03-21 MEDIUM 6.1 CVE-2018-19525 An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add a… Cumilon Isg 600c Firmware No fix yet Fix from $1,6002019-03-21 MEDIUM 6.5 CVE-2018-17996 LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content v… Layerbb Patch available Fix from $1,6002019-03-21 HIGH 8.8 CVE-2018-14575 Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject. Trash Bin No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2019-9787EPSS 41% WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration… WordPress 5.1.1+ Fix from $1,9502019-03-14 HIGH 8.8 CVE-2019-9769 PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator. Piluscart No fix yet Fix from $1,9502019-03-14 HIGH 8.8 CVE-2019-5924 Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrat… Smart Forms after 2.6.15 Fix from $1,9502019-03-12 HIGH 8.8 CVE-2019-5920 Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators… Formcraft after 1.2.1 Fix from $1,9502019-03-12 HIGH 8.8 CVE-2019-9688 sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account. Sftnow after 2018-12-29 Fix from $1,9502019-03-11 HIGH 8.8 CVE-2019-9652 There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and … Sdcms No fix yet Fix from $1,9502019-03-11 MEDIUM 6.5 CVE-2019-9598 An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds. Cscms No fix yet Fix from $1,6002019-03-07 HIGH 8.8 CVE-2018-17429 /console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account. Jtbc No fix yet Fix from $1,9502019-03-07