Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2020-04-14 CVE-2020-11003 Cross-Site Request Forgery (CSRF) vulnerability in Fraction Oasis
Oasis before version 2.15.0 has a potential DNS rebinding or CSRF vulnerability.
network
low complexity
fraction CWE-352
8.1
2020-04-12 CVE-2020-11706 Cross-Site Request Forgery (CSRF) vulnerability in Provideserver Provide FTP Server 13.1
An issue was discovered in ProVide (formerly zFTPServer) through 13.1.
network
low complexity
provideserver CWE-352
8.8
2020-04-12 CVE-2020-11701 Cross-Site Request Forgery (CSRF) vulnerability in Provideserver Provide FTP Server 13.1
An issue was discovered in ProVide (formerly zFTPServer) through 13.1.
network
low complexity
provideserver CWE-352
8.8
2020-04-10 CVE-2019-18376 Cross-Site Request Forgery (CSRF) vulnerability in Symantec Management Center 2.2/2.3/2.4
A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.
network
high complexity
symantec CWE-352
5.9
2020-04-09 CVE-2020-11553 Cross-Site Request Forgery (CSRF) vulnerability in Castlerock Snmpc Online 12.10.10
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28.
network
low complexity
castlerock CWE-352
8.8
2020-04-08 CVE-2020-5549 Cross-Site Request Forgery (CSRF) vulnerability in Plathome products
Cross-site request forgery (CSRF) vulnerability in EasyBlocks IPv6 Ver.
network
low complexity
plathome CWE-352
8.8
2020-04-08 CVE-2020-11627 Cross-Site Request Forgery (CSRF) vulnerability in Primekey Ejbca
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2.
network
low complexity
primekey CWE-352
8.8
2020-04-01 CVE-2020-5391 Cross-Site Request Forgery (CSRF) vulnerability in Auth0 Wp-Auth0
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.
network
low complexity
auth0 CWE-352
8.8
2020-03-31 CVE-2020-4238 Cross-Site Request Forgery (CSRF) vulnerability in IBM Tivoli Netcool/Impact
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2020-03-31 CVE-2020-4237 Cross-Site Request Forgery (CSRF) vulnerability in IBM Tivoli Netcool/Impact
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8