Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2017-2613 jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restar… Jenkins 2.32.2 / 2.44+ Fix from $1,6002018-05-15 HIGH 8.8 CVE-2018-11126 dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account. Doorgets No fix yet Fix from $1,9502018-05-15 MEDIUM 6.5 CVE-2018-11127 e107 2.1.7 has CSRF resulting in arbitrary user deletion. E107 Mitigation only Fix from $1,6002018-05-15 HIGH 8.8 CVE-2017-12126 An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially craft… Edr 810 Firmware No fix yet Fix from $1,9502018-05-14 HIGH 8.8 CVE-2018-11018 An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows… Pbootcms No fix yet Fix from $1,9502018-05-13 MEDIUM 6.5 CVE-2018-11003 An issue was discovered in YXcms 1.4.7. Cross-site request forgery (CSRF) vulnerability in protected/apps/admin/controller/adminController.php allows… Yxcms No fix yet Fix from $1,6002018-05-12 HIGH 8.8 CVE-2018-11004 An issue was discovered in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/admincontroller.php allows remot… Sdcms No fix yet Fix from $1,9502018-05-12 HIGH 8.8 CVE-2018-6023 Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc. Fastgate Firmware No fix yet Fix from $1,9502018-05-11 HIGH 8.8 CVE-2018-6458EPSS 10% Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF … Easy Hosting Control Panel No fix yet Fix from $1,9502018-05-11 MEDIUM 6.1 CVE-2018-10803 Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 1231… Manageengine Netflow Analyzer 12.3.125+ Fix from $1,6002018-05-10 HIGH 8.8 CVE-2018-10957 CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affecte… Dir 868l Firmware No fix yet Fix from $1,9502018-05-10 MEDIUM 5.4 CVE-2018-10806 An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/… Frogcms No fix yet Fix from $1,6002018-05-08 MEDIUM 6.5 CVE-2018-10758 The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles. Yellow No fix yet Fix from $1,6002018-05-05 HIGH 8.8 CVE-2018-10166 The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens i… Eap Controller No fix yet Fix from $1,9502018-05-03 HIGH 8.8 CVE-2013-0185 Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authenticat… Manageiq Enterprise Virtualization Manager No fix yet Fix from $1,9502018-05-01 MEDIUM 5.4 CVE-2018-10554 An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm pa… Nagios Xi No fix yet Fix from $1,6002018-04-30 HIGH 8.8 CVE-2018-10503 An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105. CSRF allows adding an administrator account via op=edituser, changing the admin… Baijiacms No fix yet Fix from $1,9502018-04-27 HIGH 8.8 CVE-2018-1479 IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actio… Bigfix Platform after 9.5.8 Fix from $1,9502018-04-27 HIGH 8.8 CVE-2018-10312 index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member. Wuzhicms No fix yet Fix from $1,9502018-04-24 HIGH 8.8 CVE-2018-10233 The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a … User Profile \& Membership 2.0.7+ Fix from $1,9502018-04-23 HIGH 8.8 CVE-2018-10295 ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account. Chemcms No fix yet Fix from $1,9502018-04-22 HIGH 8.8 CVE-2018-10265 An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI. Hongcms Mitigation only Fix from $1,9502018-04-22 HIGH 8.8 CVE-2018-10266 BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI. Beescms Mitigation only Fix from $1,9502018-04-22 HIGH 8.8 CVE-2018-10267 WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI. Wtcms No fix yet Fix from $1,9502018-04-22 HIGH 8.8 CVE-2018-10249 baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account. Baijiacms No fix yet Fix from $1,9502018-04-20 MEDIUM 6.5 CVE-2018-10248 An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_del… Wuzhicms No fix yet Fix from $1,6002018-04-20 HIGH 8.8 CVE-2018-0255 A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct … iOS Mitigation only Fix from $1,9502018-04-19 HIGH 8.8 CVE-2018-0259 A vulnerability in the web-based management interface of Cisco MATE Collector could allow an unauthenticated, remote attacker to conduct a cross-site… Mate Collector Mitigation only Fix from $1,9502018-04-19 HIGH 8.8 CVE-2018-10188 phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations… phpMyAdmin No fix yet Fix from $1,9502018-04-19 HIGH 8.8 CVE-2018-10222 An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&fr… Icms No fix yet Fix from $1,9502018-04-19