Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2018-20419 DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account. Douphp No fix yet Fix from $1,9502018-12-24 MEDIUM 6.5 CVE-2018-8892 A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to… Unified Endpoint Manager 12.9.1+ Fix from $1,6002018-12-20 HIGH 8.8 CVE-2018-1000858 GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Infor… Ubuntu Linux after 2.2.11 Fix from $1,9502018-12-20 HIGH 8.8 CVE-2018-1000843 Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contains a Cross… Luigi 2.8.0+ Fix from $1,9502018-12-20 HIGH 8.8 CVE-2018-1000846 FreshDNS version 1.0.3 and earlier contains a Cross ite Request Forgery (CSRF) vulnerability in All (authenticated) API calls in index.php / class.ma… Freshdns after 1.0.3 Fix from $1,9502018-12-20 HIGH 8.8 CVE-2018-1661 IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and … Datapower Gateway after 7.6.0.9 Fix from $1,9502018-12-20 HIGH 8.0 CVE-2018-20228 Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF. Subsonic No fix yet Fix from $1,9502018-12-19 HIGH 8.8 CVE-2018-20231 Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the … Two Factor Authentication 1.3.13+ Fix from $1,9502018-12-19 MEDIUM 6.5 CVE-2018-19829 Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is kn… Integria Ims No fix yet Fix from $1,6002018-12-18 MEDIUM 6.5 CVE-2018-18921 PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action. Php Server Monitor 3.3.2+ Fix from $1,6002018-12-18 HIGH 8.8 CVE-2018-20188 FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account. Fuel Cms No fix yet Fix from $1,9502018-12-17 MEDIUM 6.5 CVE-2018-18246 Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/m… Icinga Web 2 2.6.2+ Fix from $1,6002018-12-17 HIGH 8.8 CVE-2018-1926 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of u… Websphere Application Server after 9.0.0.9 Fix from $1,9502018-12-12 HIGH 8.8 CVE-2018-19969 phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is … phpMyAdmin 4.8.4+ Fix from $1,9502018-12-11 HIGH 8.8 CVE-2018-20015 YzmCMS v5.2 has admin/role/add.html CSRF. Yzmcms No fix yet Fix from $1,9502018-12-10 HIGH 8.8 CVE-2018-19923 An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF. Sales \& Company Management System after 2018-06-06 Fix from $1,9502018-12-06 HIGH 7.5 CVE-2018-19911 FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or … Freeswitch after 1.8.2 Fix from $1,9502018-12-06 HIGH 8.8 CVE-2018-1002103 In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is… Minikube after 0.29.0 Fix from $1,9502018-12-05 HIGH 8.8 CVE-2018-16634 Pluck v4.7.7 allows CSRF via admin.php?action=settings. Pluck No fix yet Fix from $1,9502018-12-04 HIGH 8.8 CVE-2018-7831 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340… Modicom M340 Firmware No fix yet Fix from $1,9502018-11-30 HIGH 8.8 CVE-2018-1927 IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted … Storediq 7.6.0.17+ Fix from $1,9502018-11-30 MEDIUM 6.5 CVE-2018-19621 server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team. Showdoc No fix yet Fix from $1,6002018-11-28 HIGH 8.8 CVE-2018-14892 Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changi… Nsa325 V2 Firmware No fix yet Fix from $1,9502018-11-27 HIGH 8.8 CVE-2018-16854 A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token t… Moodle 3.1.15 / 3.3.9+ Fix from $1,9502018-11-26 HIGH 8.8 CVE-2018-19555 tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password. Teleport No fix yet Fix from $1,9502018-11-26 HIGH 8.8 CVE-2018-19560 BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account. Bagecms No fix yet Fix from $1,9502018-11-26 HIGH 8.8 CVE-2018-19561 sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account. Sikcms No fix yet Fix from $1,9502018-11-26 MEDIUM 6.5 CVE-2018-19544 JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news. Jeecms No fix yet Fix from $1,6002018-11-26 HIGH 8.8 CVE-2018-19545 JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user. Jeecms No fix yet Fix from $1,9502018-11-26 HIGH 8.8 CVE-2018-19546 JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter. Jtbc Php No fix yet Fix from $1,9502018-11-26