Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-07-05 CVE-2019-5968 Cross-Site Request Forgery (CSRF) vulnerability in Weseek Growi
Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.
network
low complexity
weseek CWE-352
8.8
2019-07-05 CVE-2019-5963 Cross-Site Request Forgery (CSRF) vulnerability in Zoho Salesiq
Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
zoho CWE-352
8.8
2019-07-05 CVE-2019-5960 Cross-Site Request Forgery (CSRF) vulnerability in Custom4Web WP Open Graph
Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
custom4web CWE-352
8.8
2019-07-03 CVE-2019-12851 Cross-Site Request Forgery (CSRF) vulnerability in Jetbrains Youtrack
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack.
network
low complexity
jetbrains CWE-352
8.8
2019-07-03 CVE-2019-5630 Cross-Site Request Forgery (CSRF) vulnerability in Rapid7 Nexpose
A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68.
network
low complexity
rapid7 CWE-352
8.8
2019-07-03 CVE-2018-10986 Cross-Site Request Forgery (CSRF) vulnerability in Open-Xchange OX Guard 2.8.0
OX Guard 2.8.0 has CSRF.
network
low complexity
open-xchange CWE-352
8.8
2019-07-03 CVE-2018-11427 Cross-Site Request Forgery (CSRF) vulnerability in Moxa products
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.
network
low complexity
moxa CWE-352
8.8
2019-07-02 CVE-2017-8406 Cross-Site Request Forgery (CSRF) vulnerability in Dlink Dcs-1130 Firmware
An issue was discovered on D-Link DCS-1130 devices.
network
low complexity
dlink CWE-352
8.8
2019-07-02 CVE-2017-8407 Cross-Site Request Forgery (CSRF) vulnerability in Dlink Dcs-1130 Firmware
An issue was discovered on D-Link DCS-1130 devices.
network
low complexity
dlink CWE-352
8.8
2019-07-02 CVE-2019-7262 Cross-Site Request Forgery (CSRF) vulnerability in Nortekcontrol products
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
network
low complexity
nortekcontrol CWE-352
8.8