Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2018-11349 The administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_by_name, search_by_hash, and … Jirafeau 3.4.1+ Fix from $1,9502018-07-07 HIGH 8.8 CVE-2018-13340 Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request. Gleez Cms No fix yet Fix from $1,9502018-07-05 HIGH 8.8 CVE-2018-12739 In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266. Beescms No fix yet Fix from $1,9502018-07-05 HIGH 8.8 CVE-2018-13031 DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account. Damicms No fix yet Fix from $1,9502018-07-05 HIGH 8.8 CVE-2016-10522 rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a re… Rails Admin 1.1.1+ Fix from $1,9502018-07-05 HIGH 8.8 CVE-2018-11636 Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to execu… Powermedia Xms after 3.5 Fix from $1,9502018-07-03 HIGH 8.8 CVE-2018-13067 /upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's … Opencart after 3.0.2.0 Fix from $1,9502018-07-02 HIGH 8.8 CVE-2018-12529 An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user… N150 Firmware No fix yet Fix from $1,9502018-07-02 HIGH 8.8 CVE-2018-12574 CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices. Tl Wr841n Firmware Mitigation only Fix from $1,9502018-07-02 HIGH 8.8 CVE-2018-13040 OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerability can add an account (at the admin level) via the index.php/man_user/insert URI. Opensid No fix yet Fix from $1,9502018-07-01 HIGH 8.8 CVE-2018-13032 ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI. Shieldlink Sl175ehq Firmware No fix yet Fix from $1,9502018-07-01 HIGH 8.8 CVE-2018-13010 WSTMall v1.9.1_170316 has CSRF via the index.php?m=Admin&c=Users&a=edit URI to add a user account. Wstmall No fix yet Fix from $1,9502018-06-29 MEDIUM 6.5 CVE-2018-12971 EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users. Easycms No fix yet Fix from $1,6002018-06-29 HIGH 8.8 CVE-2018-11447 A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a Cross-Site Request Forgery (CSRF… Scalance M875 Firmware Mitigation only Fix from $1,9502018-06-26 MEDIUM 6.5 CVE-2018-1000505 Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybod… Tooltipy No fix yet Fix from $1,6002018-06-26 HIGH 8.8 CVE-2018-1000506 Metronet Tag Manager version 1.2.7 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page /wp-admin/options-general.php?page=metr… Metronet Tag Manager No fix yet Fix from $1,9502018-06-26 MEDIUM 6.5 CVE-2018-1000507 WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify u… Wp User Groups No fix yet Fix from $1,6002018-06-26 HIGH 8.8 CVE-2018-12603 Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users… Lfcms No fix yet Fix from $1,9502018-06-25 HIGH 8.8 CVE-2018-12602 A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily. Lfcms No fix yet Fix from $1,9502018-06-25 HIGH 8.8 CVE-2018-12659 SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter. Slims Akasia No fix yet Fix from $1,9502018-06-22 HIGH 8.8 CVE-2018-0363 A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could allow an un… Unified Communications Manager Im And Presence Service Mitigation only Fix from $1,9502018-06-21 HIGH 8.8 CVE-2018-0364 A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker … Unified Communications Domain Manager Mitigation only Fix from $1,9502018-06-21 HIGH 8.8 CVE-2018-0365 A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct… Secure Firewall Management Center Mitigation only Fix from $1,9502018-06-21 HIGH 8.8 CVE-2018-6563 Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack t… Encryption Gateway after 6.0.0 Fix from $1,9502018-06-20 HIGH 8.8 CVE-2018-12582 An issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&job=newaccount URI. Akcms No fix yet Fix from $1,9502018-06-19 MEDIUM 6.5 CVE-2018-12583 An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php. Akcms No fix yet Fix from $1,6002018-06-19 HIGH 8.8 CVE-2018-6496 Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which coul… Universal Cmbd Browser after 4.15.1 Fix from $1,9502018-06-16 HIGH 8.8 CVE-2018-6497 Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10… Cms Server after 11.0 Fix from $1,9502018-06-16 HIGH 8.8 CVE-2018-12114 Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts. Maccms No fix yet Fix from $1,9502018-06-14 HIGH 8.8 CVE-2018-12354 Knowage (formerly SpagoBI) 6.1.1 allows CSRF via every form, as demonstrated by a /knowage/restful-services/2.0/analyticalDrivers/ POST request. Knowage Mitigation only Fix from $1,9502018-06-13