Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2020-01-28 CVE-2020-8424 Cross-Site Request Forgery (CSRF) vulnerability in Cups Easy Project Cups Easy 1.0
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
network
low complexity
cups-easy-project CWE-352
8.8
2020-01-28 CVE-2020-8420 Cross-Site Request Forgery (CSRF) vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.15.
network
low complexity
joomla CWE-352
8.8
2020-01-28 CVE-2020-8419 Cross-Site Request Forgery (CSRF) vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.15.
network
low complexity
joomla CWE-352
8.8
2020-01-28 CVE-2020-8417 Cross-Site Request Forgery (CSRF) vulnerability in Codesnippets Code Snippets
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
network
low complexity
codesnippets CWE-352
8.8
2020-01-28 CVE-2013-3093 Cross-Site Request Forgery (CSRF) vulnerability in Asus products
ASUS RT-N56U devices allow CSRF.
network
low complexity
asus CWE-352
8.8
2020-01-28 CVE-2015-5483 Cross-Site Request Forgery (CSRF) vulnerability in Private Only Project Private Only 3.5.1
Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modify PHP files via unspecified vectors, or (4) conduct cross-site scripting (XSS) attacks via the po_logo parameter in the privateonly.php page to wp-admin/options-general.php.
network
low complexity
private-only-project CWE-352
8.8
2020-01-28 CVE-2013-4865 Cross-Site Request Forgery (CSRF) vulnerability in Micasaverde Veralite Firmware 1.5.408
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.
network
low complexity
micasaverde CWE-352
6.5
2020-01-26 CVE-2020-7991 Cross-Site Request Forgery (CSRF) vulnerability in Adive Framework 2.0.8
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
network
low complexity
adive CWE-352
8.8
2020-01-23 CVE-2014-2050 Cross-Site Request Forgery (CSRF) vulnerability in Owncloud
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
network
low complexity
owncloud CWE-352
6.5
2020-01-23 CVE-2019-16513 Cross-Site Request Forgery (CSRF) vulnerability in Connectwise Control 19.3.25270.7185
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
network
low complexity
connectwise CWE-352
8.8