Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.1 CVE-2018-15677 The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF. Xbtit Patch available Fix from $1,6002018-09-05 HIGH 8.8 CVE-2018-15682 An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of sending pr… Xbtit after 2.5.4 Fix from $1,9502018-09-05 HIGH 8.8 CVE-2018-14769 VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF. Camera No fix yet Fix from $1,9502018-09-05 MEDIUM 6.5 CVE-2018-16458 An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication of any article. Baigo Cms No fix yet Fix from $1,6002018-09-04 HIGH 8.8 CVE-2018-16447 Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF. Frogcms No fix yet Fix from $1,9502018-09-04 HIGH 8.8 CVE-2018-16448 Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/ad… Cscms No fix yet Fix from $1,9502018-09-04 MEDIUM 6.5 CVE-2018-16449 OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting … Onethink No fix yet Fix from $1,6002018-09-04 HIGH 8.8 CVE-2018-16431 admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account. Yfcmf No fix yet Fix from $1,9502018-09-04 HIGH 8.8 CVE-2018-16416 Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's pass… Fuel Cms No fix yet Fix from $1,9502018-09-03 HIGH 8.8 CVE-2018-16387 An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add. Elefantcms 2.0.5+ Fix from $1,9502018-09-03 HIGH 8.8 CVE-2018-16380 An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add an admin account. Ogma Cms No fix yet Fix from $1,9502018-09-03 HIGH 8.8 CVE-2018-16366 An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF. Icms No fix yet Fix from $1,9502018-09-02 HIGH 8.8 CVE-2018-16365 An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF. Icms No fix yet Fix from $1,9502018-09-02 HIGH 8.8 CVE-2018-16345 An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTa… Easycms No fix yet Fix from $1,9502018-09-02 MEDIUM 6.5 CVE-2018-16337 An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/s… Cscms No fix yet Fix from $1,6002018-09-02 HIGH 8.8 CVE-2018-16338 An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subseq… Auracms No fix yet Fix from $1,9502018-09-02 HIGH 8.8 CVE-2018-16339 An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser. Empirecms No fix yet Fix from $1,9502018-09-02 HIGH 8.8 CVE-2018-16331 admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password. Damicms No fix yet Fix from $1,9502018-09-02 HIGH 8.8 CVE-2018-16332 An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability. Icms No fix yet Fix from $1,9502018-09-02 HIGH 8.8 CVE-2018-16314 An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is… Icms No fix yet Fix from $1,9502018-09-01 MEDIUM 6.5 CVE-2018-16315 In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add. Waimai Super Cms No fix yet Fix from $1,6002018-09-01 HIGH 8.8 CVE-2018-11718 Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow CSRF. Pc2r Firmware after 3.6.0 Fix from $1,9502018-08-30 HIGH 8.8 CVE-2018-15121 An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 an… Aspnet Mitigation only Fix from $1,9502018-08-29 HIGH 8.8 CVE-2018-15884 RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter. Mp C4504ex Firmware No fix yet Fix from $1,9502018-08-28 HIGH 8.8 CVE-2018-15901 e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators. E107 No fix yet Fix from $1,9502018-08-28 HIGH 8.8 CVE-2014-6046 Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecifi… Phpmyfaq 2.8.13+ Fix from $1,9502018-08-28 HIGH 8.8 CVE-2018-15850 An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user. Redaxo Cms Mitigation only Fix from $1,9502018-08-25 HIGH 8.8 CVE-2018-15851 An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user/add. Flexo Cms Mitigation only Fix from $1,9502018-08-25 HIGH 8.8 CVE-2018-15844 An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin… Damicms No fix yet Fix from $1,9502018-08-25 HIGH 8.8 CVE-2018-15845 There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add. Gleez Cms No fix yet Fix from $1,9502018-08-25