Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2018-0216 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond… Identity Services Engine Mitigation only Fix from $1,6002018-03-08 HIGH 8.8 CVE-2018-7565 CSRF exists on Polycom QDX 6000 devices. Qdx 6000 Firmware No fix yet Fix from $1,9502018-03-07 HIGH 8.8 CVE-2018-7746 An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/channel/modifychannel. For example… Razor No fix yet Fix from $1,9502018-03-07 HIGH 8.8 CVE-2018-7720 A cross-site request forgery (CSRF) vulnerability exists in Western Bridge Cobub Razor 0.7.2 via /index.php?/user/createNewUser/, resulting in accoun… Razor No fix yet Fix from $1,9502018-03-07 HIGH 8.8 CVE-2017-11649 Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to hijack… Vigorap 910c Firmware No fix yet Fix from $1,9502018-03-07 HIGH 8.8 CVE-2018-7733 An issue was discovered in YxtCMF 3.1. RbacController.class.php has CSRF, as demonstrated by modifying an administrator account via index.php/admin/u… Yxtcmf after 3.1 Fix from $1,9502018-03-06 MEDIUM 5.4 CVE-2018-7724 The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, rel… Piwigo No fix yet Fix from $1,6002018-03-06 HIGH 8.8 CVE-2018-7307 The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter. Auth0.js 9.3+ Fix from $1,9502018-03-06 HIGH 8.8 CVE-2018-7634 An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functi… Tuleap Patch available Fix from $1,9502018-03-01 HIGH 8.8 CVE-2018-7590 CSRF exists in Hoosk 1.7.0 via /admin/users/new/add, resulting in account creation. Hoosk Mitigation only Fix from $1,9502018-03-01 HIGH 8.8 CVE-2016-0295 Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the … Bigfix Platform 9.5.2+ Fix from $1,9502018-02-28 HIGH 8.8 CVE-2018-0520 Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of ad… Fs010w Firmware Mitigation only Fix from $1,9502018-02-23 MEDIUM 5.4 CVE-2018-0146 A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site requ… Data Center Analytics Framework Mitigation only Fix from $1,6002018-02-22 HIGH 8.8 CVE-2018-0148 A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Soft… Ucs Director Mitigation only Fix from $1,9502018-02-22 HIGH 8.8 CVE-2018-7308 A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any fil… Hosting after 2018-02-11 Fix from $1,9502018-02-21 HIGH 8.0 CVE-2016-0348 Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the … Tririga Application Platform Mitigation only Fix from $1,9502018-02-21 HIGH 7.5 CVE-2017-12415 OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition… Eshop 4.9.10 / 4.10.5+ Fix from $1,9502018-02-20 MEDIUM 6.1 CVE-2018-6940 A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunctio… Nat32 No fix yet Fix from $1,6002018-02-20 HIGH 8.8 CVE-2018-6941 A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjuncti… Nat32 No fix yet Fix from $1,9502018-02-20 HIGH 8.8 CVE-2017-16756 An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=p… Helpspot after 4.7.1 Fix from $1,9502018-02-19 HIGH 8.8 CVE-2018-7219 application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/ind… Nonecms No fix yet Fix from $1,9502018-02-19 HIGH 8.0 CVE-2018-7216 Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated use… Bravo Solution No fix yet Fix from $1,9502018-02-18 HIGH 8.8 CVE-2018-7176 FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Perm… Frontaccounting No fix yet Fix from $1,9502018-02-16 HIGH 8.8 CVE-2017-5781 A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found. Matrix Operating Environment No fix yet Fix from $1,9502018-02-15 HIGH 8.8 CVE-2017-5796 A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found. J9627a Firmware Mitigation only Fix from $1,9502018-02-15 HIGH 8.0 CVE-2016-8513 A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior … Version Control Repository Manager 7.6+ Fix from $1,9502018-02-15 HIGH 8.1 CVE-2017-9963 A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with… Powerscada Anywhere Mitigation only Fix from $1,9502018-02-12 HIGH 8.0 CVE-2018-6888 An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: usin… Typesetter No fix yet Fix from $1,9502018-02-12 HIGH 8.8 CVE-2018-1000053 LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causi… Limesurvey Patch available Fix from $1,9502018-02-09 HIGH 8.8 CVE-2017-17552 /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resultin… Manageengine Admanager Plus 6.6+ Fix from $1,9502018-02-07