Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2018-14966 An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF. Emlsoft No fix yet Fix from $1,9502018-08-06 HIGH 8.8 CVE-2018-14958 An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php. Weaselcms No fix yet Fix from $1,9502018-08-05 HIGH 8.8 CVE-2018-14959 An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI. Weaselcms No fix yet Fix from $1,9502018-08-05 HIGH 8.8 CVE-2018-14926 Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request. Banco Mitigation only Fix from $1,9502018-08-03 HIGH 8.8 CVE-2018-14910 SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The… Seacms No fix yet Fix from $1,9502018-08-03 HIGH 8.8 CVE-2018-14908 Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupVie… Syncthru Web Service No fix yet Fix from $1,9502018-08-03 HIGH 8.8 CVE-2018-0413 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond… Identity Services Engine Software No fix yet Fix from $1,9502018-08-01 HIGH 7.5 CVE-2018-1999027 An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that… Saltstack after 3.1.6 Fix from $1,9502018-08-01 HIGH 8.8 CVE-2018-14603 An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. CSRF can occur in t… GitLab 10.8.7 / 11.0.5+ Fix from $1,9502018-07-27 HIGH 8.8 CVE-2018-14582 index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account. Bagecms No fix yet Fix from $1,9502018-07-24 HIGH 8.8 CVE-2018-14583 xyhai.php?s=/Auth/addUser in XYHCMS 3.5 allows CSRF to add a background administrator account. Xyhcms No fix yet Fix from $1,9502018-07-24 HIGH 8.8 CVE-2017-3187 The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a … Dotcms after 3.7.1 Fix from $1,9502018-07-24 HIGH 8.8 CVE-2018-14420 MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=… Metinfo No fix yet Fix from $1,9502018-07-20 HIGH 8.8 CVE-2018-14421 SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admi… Seacms Mitigation only Fix from $1,9502018-07-20 HIGH 8.8 CVE-2018-0402 Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, … Unified Contact Center Express Mitigation only Fix from $1,9502018-07-18 HIGH 8.8 CVE-2018-14331 An issue was discovered in XiaoCms X1 v20140305. There is a CSRF vulnerability to change the administrator account password via admin/index.php?c=ind… Xiaocms X1 No fix yet Fix from $1,9502018-07-17 HIGH 8.8 CVE-2018-14068 An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Admin&c=manager&a=add. Srcms No fix yet Fix from $1,9502018-07-15 HIGH 8.8 CVE-2018-14069 An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add a user account via admin.php?m=Admin&c=member&a=add. Srcms Mitigation only Fix from $1,9502018-07-15 HIGH 8.8 CVE-2016-6578 CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability. An attacker can perform act… Filecloud after 13.0.0.32841 Fix from $1,9502018-07-13 HIGH 8.8 CVE-2016-6557 In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify … Rp Ac52 Firmware after 1.0.1.1s Fix from $1,9502018-07-13 HIGH 8.8 CVE-2018-1000206 JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF a… Artifactory 6.1.0+ Fix from $1,9502018-07-13 HIGH 8.8 CVE-2018-14029 CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the ac… Witycms No fix yet Fix from $1,9502018-07-13 HIGH 8.8 CVE-2018-14014 In waimai Super Cms 20150505, there is a CSRF vulnerability that can add an admin account via admin.php?m=Member&a=adminadd. Super Cms No fix yet Fix from $1,9502018-07-12 HIGH 8.8 CVE-2018-12540 In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter.… Vert.x after 3.5.2 Fix from $1,9502018-07-12 HIGH 8.8 CVE-2018-10895 qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious websi… Qutebrowser 1.4.1+ Fix from $1,9502018-07-12 MEDIUM 6.5 CVE-2018-10232 Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack t… Topdesk 8.05.017+ Fix from $1,6002018-07-11 HIGH 8.8 CVE-2018-13989 Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by… Grundig Smart Inter\@ctive Firmware No fix yet Fix from $1,9502018-07-11 HIGH 8.8 CVE-2018-13793 Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web Verificati… Flexicapture Mitigation only Fix from $1,9502018-07-09 HIGH 8.8 CVE-2018-13444 An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_manager.php?action=save&id=2. Seacms No fix yet Fix from $1,9502018-07-08 HIGH 8.8 CVE-2018-13445 An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add a user account via adm1n/admin_manager.php?action=add. Seacms No fix yet Fix from $1,9502018-07-08