Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2018-11406 An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and … Symfony 2.7.48 / 2.8.41+ Fix from $1,9502018-06-13 HIGH 8.8 CVE-2017-5394 A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript even… Firefox 51.0+ Fix from $1,9502018-06-11 HIGH 8.8 CVE-2014-0594 In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without … Open Build Service 2.4.6+ Fix from $1,9502018-06-08 HIGH 8.8 CVE-2018-8925 Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attac… Photo Station 6.3-2975 / 6.8.5-3471+ Fix from $1,9502018-06-08 HIGH 8.8 CVE-2018-1514 IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute mal… Robotic Process Automation With Automation Anywhere Patch available Fix from $1,9502018-06-07 HIGH 8.8 CVE-2017-7906 In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow… Ip Gateway Firmware after 3.39 Fix from $1,9502018-06-06 HIGH 8.8 CVE-2017-7635 QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections. Nas Proxy Server 1.3.0+ Fix from $1,9502018-06-05 MEDIUM 6.1 CVE-2018-1432 IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker t… Infosphere Information Server Mitigation only Fix from $1,6002018-06-05 HIGH 8.8 CVE-2018-11679 An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archiv… Cmseasy No fix yet Fix from $1,9502018-06-02 MEDIUM 6.5 CVE-2018-11680 An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be … Cmseasy No fix yet Fix from $1,6002018-06-02 HIGH 8.8 CVE-2018-11538EPSS 13% servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token B… Searchblox No fix yet Fix from $1,9502018-06-01 HIGH 8.8 CVE-2018-11670 An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content para… Greencms No fix yet Fix from $1,9502018-06-01 HIGH 8.8 CVE-2018-11671 An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserha… Greencms No fix yet Fix from $1,9502018-06-01 MEDIUM 6.5 CVE-2018-11632 An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tr… Add Social Share Messenger Buttons Whatsapp And Viber No fix yet Fix from $1,6002018-05-31 MEDIUM 6.5 CVE-2018-11633 An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can be tricked into visiting a cra… Woo Checkout For Digital Goods No fix yet Fix from $1,6002018-05-31 HIGH 8.8 CVE-2016-10529 Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page th… Droppy 3.5.0+ Fix from $1,9502018-05-31 HIGH 8.8 CVE-2015-7610 Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 … Zimbra Collaboration Suite after 8.8.8 Fix from $1,9502018-05-30 HIGH 8.8 CVE-2018-11527 An issue was discovered in CScms v4.1. A Cross-site request forgery (CSRF) vulnerability in plugins/sys/admin/Sys.php allows remote attackers to chan… Cscms No fix yet Fix from $1,9502018-05-29 HIGH 8.8 CVE-2018-11500 An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUse… Publiccms No fix yet Fix from $1,9502018-05-26 HIGH 8.8 CVE-2018-11501 PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS. Website Seller Script No fix yet Fix from $1,9502018-05-26 HIGH 8.8 CVE-2018-11493 An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add. Wuzhicms No fix yet Fix from $1,9502018-05-26 HIGH 8.8 CVE-2017-9641 PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrad… Pi Coresight after 2016-r2 Fix from $1,9502018-05-25 HIGH 8.8 CVE-2018-11442 A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding… Easyservice Billing No fix yet Fix from $1,9502018-05-25 HIGH 8.8 CVE-2018-11445 A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with… Easyservice Billing No fix yet Fix from $1,9502018-05-25 HIGH 8.8 CVE-2018-11405 Kliqqi 2.0.2 has CSRF in admin/admin_users.php. Kliqqi Cms No fix yet Fix from $1,9502018-05-24 HIGH 8.8 CVE-2018-11371 SkyCaiji 1.2 allows CSRF to add an Administrator user. Skycaiji No fix yet Fix from $1,9502018-05-22 MEDIUM 6.5 CVE-2018-11092 An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?emp… Admin Notes Patch available Fix from $1,6002018-05-21 MEDIUM 6.5 CVE-2018-11096 Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the target's account information re… Horse Market Sell \& Rent Portal No fix yet Fix from $1,6002018-05-21 HIGH 8.8 CVE-2018-1434 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6… Storwize V7000 Firmware 7.5.0.14 / 7.7.1.9+ Fix from $1,9502018-05-17 HIGH 8.8 CVE-2018-0270 A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker t… Iot Field Network Director No fix yet Fix from $1,9502018-05-17