Total
7856 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-15197 | 1 Onethink | 1 Onethink | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow administrator privileges. | |||||
CVE-2018-15193 | 1 Gogs | 1 Gogs | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link. | |||||
CVE-2018-15187 | 1 Advanced Real Estate Script Project | 1 Advanced Real Estate Script | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php. | |||||
CVE-2018-15186 | 1 Chartered Accountant \ | 1 Auditor Website Project | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php. | |||||
CVE-2018-15177 | 1 Gxlcms | 1 Gxlcms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account. | |||||
CVE-2018-15121 | 1 Auth0 | 2 Aspnet, Aspnet-owin | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations. | |||||
CVE-2018-14978 | 1 Q-cms | 1 Qcms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI. | |||||
CVE-2018-14966 | 1 Emlsoft Project | 1 Emlsoft | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF. | |||||
CVE-2018-14965 | 1 Emlsoft Project | 1 Emlsoft | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=address&do=add page allows CSRF. | |||||
CVE-2018-14963 | 1 Zzcms | 1 Zzcms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI. | |||||
CVE-2018-14960 | 1 Xiao5ucompany Project | 1 Xiao5ucompany | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Xiao5uCompany 1.7 has CSRF via admin/Admin.asp. | |||||
CVE-2018-14959 | 1 Weaselcms Project | 1 Weaselcms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI. | |||||
CVE-2018-14958 | 1 Weaselcms Project | 1 Weaselcms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php. | |||||
CVE-2018-14930 | 1 Polarisft | 1 Intellect Core Banking | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebApp/gcmsRefInsert?name=SUPP URI. | |||||
CVE-2018-14926 | 1 Matera | 1 Banco | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request. | |||||
CVE-2018-14910 | 1 Seacms | 1 Seacms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The code is executed by visiting adm1n/admin_ip.php or data/admin/ip.php. This can also be exploited through CSRF. | |||||
CVE-2018-14908 | 1 Samsung | 1 Syncthru Web Service | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupView.sws for a "Print emails sent" action. | |||||
CVE-2018-14892 | 1 Zyxel | 2 Nsa325 V2, Nsa325 V2 Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms. | |||||
CVE-2018-14783 | 1 Netcommwireless | 2 Nwl-25, Nwl-25 Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forgery condition can occur, allowing an attacker to change passwords of the device remotely. | |||||
CVE-2018-14769 | 1 Vivotek | 1 Camera | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF. |