Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2021-06-10 CVE-2021-31659 Cross-Site Request Forgery (CSRF) vulnerability in Tp-Link Tl-Sg2005 Firmware and Tl-Sg2008 Firmware
TP-Link TL-SG2005, TL-SG2008, etc.
network
low complexity
tp-link CWE-352
8.8
2021-06-10 CVE-2021-34547 Cross-Site Request Forgery (CSRF) vulnerability in Paessler Prtg Network Monitor 20.1.55.1775
PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.
network
low complexity
paessler CWE-352
4.3
2021-06-09 CVE-2021-29995 Cross-Site Request Forgery (CSRF) vulnerability in Cloverdx
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution).
network
low complexity
cloverdx CWE-352
8.8
2021-06-08 CVE-2021-26474 Cross-Site Request Forgery (CSRF) vulnerability in Vembu BDR Suite and Offsite DR
Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)
network
low complexity
vembu CWE-352
8.8
2021-06-08 CVE-2020-26516 Cross-Site Request Forgery (CSRF) vulnerability in Intland Codebeamer
A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4.
network
low complexity
intland CWE-352
8.8
2021-06-07 CVE-2020-18264 Cross-Site Request Forgery (CSRF) vulnerability in Simple-Log Project Simple-Log 1.6
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member".
network
low complexity
simple-log-project CWE-352
8.8
2021-06-07 CVE-2020-18265 Cross-Site Request Forgery (CSRF) vulnerability in Simple-Log Project Simple-Log 1.6
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_add_member".
network
low complexity
simple-log-project CWE-352
8.8
2021-06-04 CVE-2020-36140 Cross-Site Request Forgery (CSRF) vulnerability in Bloofox Bloofoxcms 0.5.2.1
BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).
network
low complexity
bloofox CWE-352
6.5
2021-06-03 CVE-2020-35972 Cross-Site Request Forgery (CSRF) vulnerability in Yzmcms 5.8
An issue was discovered in YzmCMS V5.8.
network
low complexity
yzmcms CWE-352
4.3
2021-05-28 CVE-2020-26641 Cross-Site Request Forgery (CSRF) vulnerability in Idreamsoft Icms 7.0.16
A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts.
network
low complexity
idreamsoft CWE-352
8.8