Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2021-02-12 CVE-2021-20641 Cross-Site Request Forgery (CSRF) vulnerability in Logitech Lan-W300N/Rs Firmware
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL.
network
low complexity
logitech CWE-352
6.5
2021-02-12 CVE-2021-20636 Cross-Site Request Forgery (CSRF) vulnerability in Logitech Lan-W300N/Pr5B Firmware
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL.
network
low complexity
logitech CWE-352
6.5
2021-02-11 CVE-2020-13186 Cross-Site Request Forgery (CSRF) vulnerability in Teradici Cloud Access Connector
An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.
network
low complexity
teradici CWE-352
6.5
2021-02-11 CVE-2021-20403 Cross-Site Request Forgery (CSRF) vulnerability in IBM Security Verify Information Queue 1.0.6/1.0.7
IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2021-02-09 CVE-2020-28644 Cross-Site Request Forgery (CSRF) vulnerability in Owncloud
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints.
network
low complexity
owncloud CWE-352
4.3
2021-02-09 CVE-2020-35943 Cross-Site Request Forgery (CSRF) vulnerability in Imagely Nextgen Gallery
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload.
network
low complexity
imagely CWE-352
6.5
2021-02-09 CVE-2020-13460 Cross-Site Request Forgery (CSRF) vulnerability in Tufin Securetrack 18.1
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.
network
low complexity
tufin CWE-352
8.8
2021-02-06 CVE-2021-22500 Cross-Site Request Forgery (CSRF) vulnerability in Microfocus Application Performance Management 9.40/9.50/9.51
Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51.
network
low complexity
microfocus CWE-352
6.5
2021-02-05 CVE-2021-20652 Cross-Site Request Forgery (CSRF) vulnerability in Name Directory Project Name Directory
Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
name-directory-project CWE-352
8.8
2021-02-04 CVE-2020-4827 Cross-Site Request Forgery (CSRF) vulnerability in IBM API Connect
IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
4.3