Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2018-5658 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php. Responsive Coming Soon Page No fix yet Fix from $1,9502018-01-13 HIGH 8.8 CVE-2018-5669 An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.php. Read And Understood No fix yet Fix from $1,9502018-01-13 HIGH 8.8 CVE-2016-0335 Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SI… Security Identity Manager Patch available Fix from $1,9502018-01-12 HIGH 8.8 CVE-2017-16886EPSS 7% The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorize… Lm53q1 Firmware No fix yet Fix from $1,9502018-01-12 HIGH 8.8 CVE-2018-5368 The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php. Srbtranslatin No fix yet Fix from $1,9502018-01-12 HIGH 8.8 CVE-2018-5361 The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php. Wpglobus No fix yet Fix from $1,9502018-01-12 HIGH 8.8 CVE-2012-0699 Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the … Family Connections Cms after 2.9.0 Fix from $1,9502018-01-11 MEDIUM 6.5 CVE-2018-0785 ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Si… Asp.net Core Patch available Fix from $1,6002018-01-10 MEDIUM 6.5 CVE-2018-5301 Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an a… Magento 2.0.10 / 2.1.2+ Fix from $1,6002018-01-08 HIGH 8.8 CVE-2018-5285 The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php. Imageinject No fix yet Fix from $1,9502018-01-08 HIGH 8.8 CVE-2017-1672 IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut… Security Key Lifecycle Manager Mitigation only Fix from $1,9502018-01-04 MEDIUM 6.8 CVE-2018-5073 Online Ticket Booking has CSRF via admin/movieedit.php. Advanced Real Estate Script No fix yet Fix from $1,6002018-01-03 HIGH 8.8 CVE-2017-1000479EPSS 33% pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, b… Pfsense 16.1.16+ Fix from $1,9502018-01-03 HIGH 8.8 CVE-2017-1000499EPSS 8% phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible t… phpMyAdmin 4.7.7+ Fix from $1,9502018-01-03 HIGH 8.0 CVE-2017-1000432 Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access Vanilla Forums 2.1.5+ Fix from $1,9502018-01-02 MEDIUM 6.8 CVE-2017-17982 PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php. Muslim Matrimonial Script No fix yet Fix from $1,6002017-12-30 HIGH 8.8 CVE-2017-17990 Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action. Biometric Shift Employee Management System No fix yet Fix from $1,9502017-12-30 HIGH 8.8 CVE-2014-0120 Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary us… Jboss Fuse after 1.2.2 Fix from $1,9502017-12-29 HIGH 8.8 CVE-2017-17960 PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php. Php Multivendor Ecommerce No fix yet Fix from $1,9502017-12-28 HIGH 8.8 CVE-2017-17936 Vanguard Marketplace Digital Products PHP has CSRF via /search. Marketplace Digital Products Php after 1.9 Fix from $1,9502017-12-28 HIGH 8.8 CVE-2017-17939 PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php. Single Theater Booking Script No fix yet Fix from $1,9502017-12-28 HIGH 8.8 CVE-2017-17903 FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel. Lynda Clone No fix yet Fix from $1,9502017-12-27 HIGH 8.8 CVE-2017-17905 PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php. Car Rental Script No fix yet Fix from $1,9502017-12-27 HIGH 8.8 CVE-2017-17908 PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general. Responsive Realestate Script No fix yet Fix from $1,9502017-12-27 HIGH 8.8 CVE-2017-17930 PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel. Professional Service Script No fix yet Fix from $1,9502017-12-27 HIGH 8.8 CVE-2017-17891 Readymade Video Sharing Script has CSRF via user-profile-edit.php. Readymade Video Sharing Script No fix yet Fix from $1,9502017-12-27 HIGH 8.8 CVE-2017-17894 Readymade Job Site Script has CSRF via the /job URI. Basic Job Site Script No fix yet Fix from $1,9502017-12-27 MEDIUM 6.8 CVE-2017-17830 Bus Booking Script has CSRF via admin/new_master.php. Bus Booking Script No fix yet Fix from $1,6002017-12-21 HIGH 8.8 CVE-2017-17827 Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration&section=main or /admin.php?page=batch_manager&mode=unit. A… Piwigo Patch available Fix from $1,9502017-12-21 HIGH 8.0 CVE-2017-5263 Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typ… Cnpilot R190v Firmware after 4.3.2-r4 Fix from $1,9502017-12-20