Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2018-15846 An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator's password via index.php?p=do… Fledrcms after 2014-02-03 Fix from $1,9502018-08-25 HIGH 8.8 CVE-2018-15848 An issue was discovered in portfolioCMS 1.0.5. There is CSRF to create new pages via admin/portfolio.php?newpage=true. Portfoliocms Mitigation only Fix from $1,9502018-08-25 MEDIUM 6.5 CVE-2018-11502 An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. A… Moderator Log Notes No fix yet Fix from $1,6002018-08-24 HIGH 8.8 CVE-2018-10884 Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could expl… Ansible Tower after 3.2.6 Fix from $1,9502018-08-22 HIGH 8.8 CVE-2018-15564 An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any page via admin/?delpage=8. Simple Cms after 2014-03-11 Fix from $1,9502018-08-20 HIGH 8.8 CVE-2018-15565 An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a page. This can … Simple Cms after 2014-03-11 Fix from $1,9502018-08-20 HIGH 8.8 CVE-2018-15568 tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html. Tp5cms after 2017-05-25 Fix from $1,9502018-08-20 MEDIUM 6.5 CVE-2018-15569 my little forum 2.4.12 allows CSRF for deletion of users. My Little Forum Mitigation only Fix from $1,6002018-08-20 HIGH 8.8 CVE-2018-14057 Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-toke… Pimcore 5.3.0+ Fix from $1,9502018-08-17 CRITICAL 9.9 CVE-2018-1712 IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input p… Api Connect after 5.0.8.3 Fix from $2,3002018-08-16 HIGH 8.8 CVE-2018-1455 IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execut… Tivoli Application Dependency Discovery Manager Mitigation only Fix from $1,9502018-08-15 MEDIUM 6.5 CVE-2018-13393 The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated t… Questions For Confluence 2.6.6+ Fix from $1,6002018-08-15 MEDIUM 6.5 CVE-2018-13394 The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed … Questions For Confluence 2.6.6+ Fix from $1,6002018-08-15 HIGH 8.8 CVE-2018-2442 In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session … Businessobjects Business Intelligence Mitigation only Fix from $1,9502018-08-14 HIGH 8.8 CVE-2018-7097 A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to … 3par Service Provider Mitigation only Fix from $1,9502018-08-14 HIGH 8.8 CVE-2018-14783 NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forgery condition can occur, allo… Nwl 25 Firmware after 2.0.29.11 Fix from $1,9502018-08-10 HIGH 8.8 CVE-2018-15186 PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php. Auditor Website Project No fix yet Fix from $1,9502018-08-10 HIGH 8.0 CVE-2018-15187 PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php. Advanced Real Estate Script No fix yet Fix from $1,9502018-08-10 MEDIUM 6.3 CVE-2018-15202 An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/template/includes/crudTreatment.p… Ecommerce No fix yet Fix from $1,6002018-08-08 MEDIUM 6.5 CVE-2018-15203 An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages. Ignitedcms after 2017-02-19 Fix from $1,6002018-08-08 HIGH 8.8 CVE-2018-15197 An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow administrator priv… Onethink No fix yet Fix from $1,9502018-08-08 HIGH 8.8 CVE-2018-15198 An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a user. Onethink No fix yet Fix from $1,9502018-08-08 HIGH 8.8 CVE-2018-15193 A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link. Gogs No fix yet Fix from $1,9502018-08-08 HIGH 8.8 CVE-2018-15177 In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account. Gxlcms Mitigation only Fix from $1,9502018-08-08 HIGH 8.8 CVE-2013-7464 In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to … Csrf Magic 1.0.4+ Fix from $1,9502018-08-08 HIGH 8.8 CVE-2018-7060 Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate… Clearpass 6.6.9 / 6.7.1+ Fix from $1,9502018-08-06 HIGH 8.8 CVE-2018-14978 An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI. Qcms No fix yet Fix from $1,9502018-08-06 HIGH 8.8 CVE-2018-14960 Xiao5uCompany 1.7 has CSRF via admin/Admin.asp. Xiao5ucompany No fix yet Fix from $1,9502018-08-06 HIGH 8.8 CVE-2018-14963 zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI. Zzcms No fix yet Fix from $1,9502018-08-06 HIGH 8.8 CVE-2018-14965 An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=address&do=add page allows CSRF. Emlsoft No fix yet Fix from $1,9502018-08-06