Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2017-15732 In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php. Phpmyfaq after 2.9.8 Fix from $1,9502017-10-22 HIGH 8.8 CVE-2017-15733 In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php. Phpmyfaq after 2.9.8 Fix from $1,9502017-10-22 HIGH 8.8 CVE-2017-15734 In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php. Phpmyfaq after 2.9.8 Fix from $1,9502017-10-22 HIGH 8.8 CVE-2017-15735 In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary. Phpmyfaq after 2.9.8 Fix from $1,9502017-10-22 HIGH 8.8 CVE-2017-15645 CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary command… Webmin after 1.850 Fix from $1,9502017-10-19 HIGH 8.8 CVE-2017-12271 A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affecte… Spa300 Firmware after 7.5.5 Fix from $1,9502017-10-19 HIGH 8.8 CVE-2015-7715 Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack th… Realtyna Property Listing 8.9.5+ Fix from $1,9502017-10-18 MEDIUM 5.7 CVE-2017-14956 AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php… Unified Security Management after 5.4.2 Fix from $1,6002017-10-18 HIGH 8.8 CVE-2014-3709 The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site… Keycloak after 1.0.2.final Fix from $1,9502017-10-18 HIGH 8.8 CVE-2017-14011 A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify … Multiflex M10a Controller Firmware Mitigation only Fix from $1,9502017-10-17 HIGH 8.8 CVE-2017-15296 The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964. Customer Relationship Management No fix yet Fix from $1,9502017-10-16 HIGH 8.8 CVE-2016-1261 J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS). Junos Mitigation only Fix from $1,9502017-10-13 CRITICAL 9.8 CVE-2016-1265 A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices manage… Junos Space after 15.1r2 Fix from $2,3002017-10-13 HIGH 8.0 CVE-2016-5789 A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions. An attacker could perform actions with the same permissions as a v… Jtc 200 Firmware Mitigation only Fix from $1,9502017-10-13 HIGH 8.0 CVE-2015-2142 Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack … Phpbugtracker after 1.6.0 Fix from $1,9502017-10-06 HIGH 8.8 CVE-2015-2143 Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentica… Phpbugtracker after 1.6.0 Fix from $1,9502017-10-06 MEDIUM 6.5 CVE-2017-15084 The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22. Metasploit after 4.14.1 Fix from $1,6002017-10-06 HIGH 8.8 CVE-2017-15063 There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to det… Subrion after 4.1.5 Fix from $1,9502017-10-06 MEDIUM 6.5 CVE-2017-1000085 Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality… Subversion after 2.8 Fix from $1,6002017-10-05 HIGH 8.8 CVE-2017-1000090 Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery… Role Based Authorization Strategy after 2.5.0 Fix from $1,9502017-10-05 MEDIUM 6.3 CVE-2017-1000091 GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to v… Github Branch Source Mitigation only Fix from $1,6002017-10-05 HIGH 7.5 CVE-2017-1000092 Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at … Git Mitigation only Fix from $1,9502017-10-05 HIGH 8.8 CVE-2017-1000093 Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed at… Poll Scm after 1.3.1 Fix from $1,9502017-10-05 HIGH 8.8 CVE-2016-6806 Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. … Wicket Mitigation only Fix from $1,9502017-10-03 HIGH 8.0 CVE-2017-14924 Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.… Tikiwiki Cms\/groupware Patch available Fix from $1,9502017-09-30 HIGH 8.0 CVE-2017-14925 Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.… Tikiwiki Cms\/groupware Patch available Fix from $1,9502017-09-30 HIGH 8.8 CVE-2015-9233 The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contac… Cp Contact Form With Paypal 1.1.6+ Fix from $1,9502017-09-30 HIGH 8.0 CVE-2017-13129 Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of ad… Zktime Web Mitigation only Fix from $1,9502017-09-26 HIGH 8.8 CVE-2017-7969 A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with… Powerscada Anywhere Patch available Fix from $1,9502017-09-26 HIGH 8.8 CVE-2015-5182 Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ. Amq Mitigation only Fix from $1,9502017-09-25