Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.3 CVE-2019-1003017 A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from… Job Import after 3.0 Fix from $1,6002019-02-06 MEDIUM 6.1 CVE-2019-7402 An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be explo… Phpmywind No fix yet Fix from $1,6002019-02-05 HIGH 8.8 CVE-2019-1000022 Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can re… Sente 1.14.0+ Fix from $1,9502019-02-04 HIGH 8.8 CVE-2019-1000003 MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_s… Mapsvg Lite No fix yet Fix from $1,9502019-02-04 HIGH 8.8 CVE-2019-7346 A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button,… Zoneminder after 1.32.3 Fix from $1,9502019-02-04 HIGH 8.8 CVE-2019-3604 Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an … Epolicy Orchestrator Mitigation only Fix from $1,9502019-02-01 HIGH 8.1 CVE-2019-6779 Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links. Cscms No fix yet Fix from $1,9502019-01-24 HIGH 7.4 CVE-2019-1658 A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct… Unified Intelligence Center Mitigation only Fix from $1,9502019-01-24 HIGH 8.8 CVE-2017-17835 In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow. Airflow after 1.8.2 Fix from $1,9502019-01-23 HIGH 8.8 CVE-2019-6507 An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allows CSRF. Insight after 2018-09-11 Fix from $1,9502019-01-22 HIGH 8.8 CVE-2019-6508 An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allows CSRF. Insight after 2018-09-11 Fix from $1,9502019-01-22 HIGH 8.8 CVE-2019-6509 An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows CSRF. Insight after 2018-09-11 Fix from $1,9502019-01-22 HIGH 8.8 CVE-2019-6510 An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSRF. Insight after 2018-09-11 Fix from $1,9502019-01-22 HIGH 8.8 CVE-2018-20728 A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php. Nedi after 1.7c Fix from $1,9502019-01-17 HIGH 8.8 CVE-2016-10738 Zenbership v107 has CSRF via admin/cp-functions/event-add.php. Zenbership No fix yet Fix from $1,9502019-01-16 HIGH 8.8 CVE-2019-6294 An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI. Easycms No fix yet Fix from $1,9502019-01-15 HIGH 8.8 CVE-2019-6249 An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_in… Hucart No fix yet Fix from $1,9502019-01-13 HIGH 8.8 CVE-2019-6244 An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL statements, and consequently exec… Usualtoolcms No fix yet Fix from $1,9502019-01-12 MEDIUM 6.5 CVE-2018-1000411 A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of … Junit after 1.25 Fix from $1,6002019-01-09 HIGH 8.1 CVE-2018-1000414 A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigF… Config File Provider after 3.1 Fix from $1,9502019-01-09 HIGH 8.1 CVE-2018-1000417 A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that … Email Extension Template after 1.0 Fix from $1,9502019-01-09 HIGH 8.8 CVE-2018-20613 TEMMOKU T1.09 Beta allows admin/user/add CSRF. Temmoku No fix yet Fix from $1,9502018-12-30 HIGH 8.8 CVE-2018-20598 UCMS 1.4.7 has ?do=user_addpost CSRF. Ucms No fix yet Fix from $1,9502018-12-30 HIGH 8.8 CVE-2018-20603 Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF. Lei Feng Tv Cms No fix yet Fix from $1,9502018-12-30 HIGH 8.8 CVE-2018-20612 UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF. Universal Website Asthis No fix yet Fix from $1,9502018-12-30 HIGH 8.8 CVE-2018-20595 A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the requ… Hsweb Patch available Fix from $1,9502018-12-30 HIGH 8.8 CVE-2018-18696 main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has… Microstrategy after 10.4.0026.0049 Fix from $1,9502018-12-28 MEDIUM 5.4 CVE-2018-20576 Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an … Arv7519rw22 Livebox 2.1 Firmware No fix yet Fix from $1,6002018-12-28 CRITICAL 9.1 CVE-2018-20577 Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi… Arv7519rw22 Livebox 2.1 Firmware No fix yet Fix from $2,3002018-12-28 HIGH 8.8 CVE-2018-19182 Engelsystem before commit hash 2e28336 allows CSRF. Engelsystem 3.0.0+ Fix from $1,9502018-12-26