Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2018-6907 A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows… Rainmachine Web Application No fix yet Fix from $1,9502018-11-01 HIGH 8.8 CVE-2018-18842 CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code. Z Blogphp No fix yet Fix from $1,9502018-10-30 HIGH 8.8 CVE-2018-18734 A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30. Catfish Cms No fix yet Fix from $1,9502018-10-29 HIGH 8.8 CVE-2018-18735 A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33. Catfish Blog No fix yet Fix from $1,9502018-10-29 HIGH 8.8 CVE-2018-18742 A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI. Semcms No fix yet Fix from $1,9502018-10-29 HIGH 8.8 CVE-2018-18712 An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f… Wuzhicms No fix yet Fix from $1,9502018-10-29 HIGH 8.8 CVE-2018-18711 An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=p… Wuzhicms No fix yet Fix from $1,9502018-10-29 HIGH 8.8 CVE-2018-9281 An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionalit… 9px Ups Firmware Mitigation only Fix from $1,9502018-10-24 HIGH 8.8 CVE-2018-18420 Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.p… Zenario No fix yet Fix from $1,9502018-10-19 HIGH 8.0 CVE-2015-4630 Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x be… Koha 3.14.16 / 3.16.12+ Fix from $1,9502018-10-18 HIGH 8.8 CVE-2018-12370 In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded… Ubuntu Linux 61.0+ Fix from $1,9502018-10-18 HIGH 8.8 CVE-2018-12364 NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect t… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-10-18 MEDIUM 6.5 CVE-2018-15438 A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to condu… Prime Collaboration Assurance Mitigation only Fix from $1,6002018-10-17 HIGH 8.8 CVE-2018-15402 A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to conduct cross-site request… Enterprise Network Virtualization Software Mitigation only Fix from $1,9502018-10-17 HIGH 8.8 CVE-2018-18436 JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI. Jtbc Php No fix yet Fix from $1,9502018-10-17 HIGH 8.8 CVE-2018-18422 UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI. Usualtoolcms No fix yet Fix from $1,9502018-10-17 HIGH 8.8 CVE-2018-18432 An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request. Destoon B2b No fix yet Fix from $1,9502018-10-17 HIGH 8.8 CVE-2018-15539 Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc. Cockpit Mitigation only Fix from $1,9502018-10-15 HIGH 8.8 CVE-2018-18316 emlog v6.0.0 has CSRF via the admin/user.php?action=new URI. Emlog No fix yet Fix from $1,9502018-10-15 HIGH 8.8 CVE-2018-18317 DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI. Dscms No fix yet Fix from $1,9502018-10-15 HIGH 8.8 CVE-2018-18215 In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account. Youke 365 No fix yet Fix from $1,9502018-10-11 HIGH 8.8 CVE-2018-12456 Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as … Nplug Firmware No fix yet Fix from $1,9502018-10-10 HIGH 7.3 CVE-2018-13800 A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface could allow a Cross-Site Reque… Simatic S7 1200 V4 Firmware 4.2.3+ Fix from $1,9502018-10-10 HIGH 8.8 CVE-2018-18201 qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account. Qibosoft No fix yet Fix from $1,9502018-10-09 HIGH 8.8 CVE-2018-17858 An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend. Joomla\! 3.8.13+ Fix from $1,9502018-10-09 HIGH 8.8 CVE-2018-18191 Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote attackers to change the admin… Finecms No fix yet Fix from $1,9502018-10-09 MEDIUM 6.5 CVE-2018-2474 SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended req… Fiori Mitigation only Fix from $1,6002018-10-09 MEDIUM 6.5 CVE-2018-15401 A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote atta… Hosted Collaboration Mediation Fulfillment Mitigation only Fix from $1,6002018-10-05 HIGH 8.8 CVE-2018-0451 A vulnerability in the web-based management interface of Cisco Tetration Analytics could allow an authenticated, remote attacker to conduct a cross-s… Tetration Analytics Mitigation only Fix from $1,9502018-10-05 HIGH 8.8 CVE-2018-0439 A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site… Meeting Server Mitigation only Fix from $1,9502018-10-05