Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2018-10223 An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html. Yzmcms No fix yet Fix from $1,6002018-04-19 MEDIUM 6.8 CVE-2018-10224 An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html. Yzmcms No fix yet Fix from $1,6002018-04-19 HIGH 8.8 CVE-2018-10185 An issue was discovered in TuziCMS v2.0.6. There is a CSRF vulnerability that can add an admin account, as demonstrated by a history.pushState call. Tuzicms No fix yet Fix from $1,9502018-04-17 HIGH 8.8 CVE-2018-10137 iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI. Uberforx No fix yet Fix from $1,9502018-04-16 HIGH 8.8 CVE-2018-10127 An issue was discovered in XYHCMS 3.5. It has CSRF via an index.php?g=Manage&m=Rbac&a=addUser request, resulting in addition of an account with the a… Xyhcms Mitigation only Fix from $1,9502018-04-16 HIGH 8.8 CVE-2018-10132 PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent paramet… Pbootcms No fix yet Fix from $1,9502018-04-16 HIGH 8.8 CVE-2018-10117 An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.php?app=members&do=save&fr… Icms No fix yet Fix from $1,9502018-04-16 HIGH 8.8 CVE-2017-0362 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token. Debian Linux 1.27.2 / 1.28.1+ Fix from $1,9502018-04-13 HIGH 8.8 CVE-2018-6934 CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3. Online Tutoring Script No fix yet Fix from $1,9502018-04-12 HIGH 8.8 CVE-2015-0151 Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authent… Dir 815 Firmware 2.07.b01+ Fix from $1,9502018-04-12 HIGH 8.8 CVE-2018-10048 iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. Eswap No fix yet Fix from $1,9502018-04-11 HIGH 8.8 CVE-2018-10030 CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php. Cms Made Simple after 2.2.7 Fix from $1,9502018-04-11 HIGH 8.8 CVE-2018-10031 CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php. Cms Made Simple after 2.2.7 Fix from $1,9502018-04-11 HIGH 8.8 CVE-2018-9923 An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article via an app=article&do=save… Icms after 7.0.7 Fix from $1,9502018-04-10 HIGH 8.8 CVE-2018-9926 An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add. Wuzhicms No fix yet Fix from $1,9502018-04-10 HIGH 8.8 CVE-2018-9927 An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add. Wuzhicms No fix yet Fix from $1,9502018-04-10 HIGH 8.8 CVE-2018-9856 Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a permission change via a /admin-… Kotti 1.3.2+ Fix from $1,9502018-04-09 HIGH 8.8 CVE-2014-5034 Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remote attackers to hijack the au… Brute Force Login Protection No fix yet Fix from $1,9502018-04-06 HIGH 8.8 CVE-2014-5072 Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the auth… Wp Security Audit Log 1.2.5+ Fix from $1,9502018-04-06 HIGH 8.8 CVE-2018-1000153 A cross-site request forgery vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTempl… Vsphere after 2.16 Fix from $1,9502018-04-05 HIGH 8.8 CVE-2018-6874 CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled. Auth0.js after 8.12.1 Fix from $1,9502018-04-04 MEDIUM 6.5 CVE-2018-8814 Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that mo… Wolf Cms No fix yet Fix from $1,6002018-04-04 HIGH 8.8 CVE-2017-3965 Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42… Network Security Manager 8.2.7.42.2+ Fix from $1,9502018-04-04 HIGH 8.8 CVE-2018-1098 A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd… Etcd after 3.3.1 Fix from $1,9502018-04-03 HIGH 8.8 CVE-2018-8893 Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code. Z Blogphp Mitigation only Fix from $1,9502018-03-31 HIGH 8.8 CVE-2018-8908 An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craf… Frog Cms No fix yet Fix from $1,9502018-03-31 HIGH 8.8 CVE-2018-9134 file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .ph… Dedecms Mitigation only Fix from $1,9502018-03-30 HIGH 8.8 CVE-2015-2009 Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before … Qradar Security Information And Event Manager 7.2.5+ Fix from $1,9502018-03-29 HIGH 8.8 CVE-2018-9108 CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privileges. Quickapps Cms Mitigation only Fix from $1,9502018-03-28 HIGH 8.8 CVE-2018-9092 There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password. Minicms No fix yet Fix from $1,9502018-03-27