Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-07-01 CVE-2019-7281 Cross-Site Request Forgery (CSRF) vulnerability in Primasystems Flexair 2.3.38
Prima Systems FlexAir, Versions 2.3.38 and prior.
network
low complexity
primasystems CWE-352
8.8
2019-07-01 CVE-2019-12826 Cross-Site Request Forgery (CSRF) vulnerability in Wpchef Widget Logic
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request that tricks administrators into adding the code.
network
low complexity
wpchef CWE-352
8.8
2019-06-27 CVE-2019-5814 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-352
6.5
2019-06-26 CVE-2019-6166 Cross-Site Request Forgery (CSRF) vulnerability in Lenovo Service Bridge
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.
network
low complexity
lenovo CWE-352
8.8
2019-06-25 CVE-2018-1858 Cross-Site Request Forgery (CSRF) vulnerability in IBM API Connect
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2019-06-24 CVE-2019-9958 Cross-Site Request Forgery (CSRF) vulnerability in Quadbase Espressreport Enterprise Server 7.0
CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.
network
low complexity
quadbase CWE-352
8.8
2019-06-21 CVE-2019-12836 Cross-Site Request Forgery (CSRF) vulnerability in Bobronix Jeditor
The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to an out-of-origin domain.
network
low complexity
bobronix CWE-352
8.8
2019-06-21 CVE-2019-1904 Cross-Site Request Forgery (CSRF) vulnerability in Cisco IOS XE 16.1.3/16.2.1/16.3.1
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
low complexity
cisco CWE-352
8.8
2019-06-20 CVE-2019-1874 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Prime Service Catalog
A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
low complexity
cisco CWE-352
8.8
2019-06-20 CVE-2019-1632 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.
network
low complexity
cisco CWE-352
8.0