Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2018-18449 EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339. Empirecms No fix yet Fix from $1,9502019-03-07 HIGH 8.8 CVE-2019-6710 Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF. Nbg 418n Firmware No fix yet Fix from $1,9502019-03-07 HIGH 8.8 CVE-2019-8437 njiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator. Njiandan Cms after 2013-05-23 Fix from $1,9502019-03-07 HIGH 8.8 CVE-2019-9625 JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account. Directadmin No fix yet Fix from $1,9502019-03-07 MEDIUM 6.5 CVE-2019-9603 MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891. Minicms No fix yet Fix from $1,6002019-03-06 HIGH 8.8 CVE-2019-6561 Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device. Iks G6824a Firmware after 4.5 Fix from $1,9502019-03-05 HIGH 8.8 CVE-2019-9549 An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 acco… Popojicms No fix yet Fix from $1,9502019-03-03 HIGH 8.8 CVE-2019-9182 There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the fi… Zzzphp No fix yet Fix from $1,9502019-02-26 HIGH 8.0 CVE-2019-9062 PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php. Online Food Ordering Script No fix yet Fix from $1,9502019-02-23 MEDIUM 6.5 CVE-2019-9048 An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&v… Pluck No fix yet Fix from $1,6002019-02-23 MEDIUM 6.5 CVE-2019-9049 An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI. Pluck No fix yet Fix from $1,6002019-02-23 MEDIUM 6.5 CVE-2019-9051 An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI. Pluck No fix yet Fix from $1,6002019-02-23 MEDIUM 6.5 CVE-2019-9052 An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI. Pluck No fix yet Fix from $1,6002019-02-23 HIGH 8.8 CVE-2019-9040 S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-2018-19332. S Cms Mitigation only Fix from $1,9502019-02-23 HIGH 8.8 CVE-2019-8910 An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF. Wtcms No fix yet Fix from $1,9502019-02-18 MEDIUM 5.7 CVE-2019-8902 An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI. Icms after 7.0.14 Fix from $1,6002019-02-18 HIGH 8.8 CVE-2019-0267 SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This… Manufacturing Integration And Intelligence Mitigation only Fix from $1,9502019-02-15 HIGH 8.8 CVE-2019-8347 BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=user URI. Beescms No fix yet Fix from $1,9502019-02-15 HIGH 8.8 CVE-2019-7737 A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit. Verydows No fix yet Fix from $1,9502019-02-11 MEDIUM 6.5 CVE-2019-7738 C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI. C.p.sub 5.3+ Fix from $1,6002019-02-11 MEDIUM 5.7 CVE-2019-7730 MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI. Mywebsql No fix yet Fix from $1,6002019-02-11 HIGH 8.8 CVE-2018-20780 Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1). Traq No fix yet Fix from $1,9502019-02-11 HIGH 8.8 CVE-2019-7566 CSZ CMS 1.1.8 has CSRF via admin/users/new/add. Csz Cms No fix yet Fix from $1,9502019-02-07 HIGH 8.8 CVE-2019-7569 An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admi… Doyo No fix yet Fix from $1,9502019-02-07 MEDIUM 6.5 CVE-2019-7570 A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI. Pbootcms No fix yet Fix from $1,6002019-02-07 MEDIUM 6.5 CVE-2019-1003022 A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads run… Monitoring after 1.74.0 Fix from $1,6002019-02-06 HIGH 8.8 CVE-2019-1003007 A cross-site request forgery vulnerability exists in Jenkins Warnings Plugin 5.0.0 and earlier in src/main/java/hudson/plugins/warnings/GroovyParser.… Warnings after 5.0.0 Fix from $1,9502019-02-06 HIGH 8.8 CVE-2019-1003008 A cross-site request forgery vulnerability exists in Jenkins Warnings Next Generation Plugin 2.1.1 and earlier in src/main/java/io/jenkins/plugins/an… Warnings Next Generation after 2.1.1 Fix from $1,9502019-02-06 MEDIUM 6.5 CVE-2019-1003012 A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-cor… Blue Ocean after 1.10.1 Fix from $1,6002019-02-06 HIGH 8.8 CVE-2019-1003016 An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimp… Job Import after 2.1 Fix from $1,9502019-02-06