Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-05-12 CVE-2018-11004 Cross-Site Request Forgery (CSRF) vulnerability in Sdcms 1.5
An issue was discovered in SDcms v1.5.
network
low complexity
sdcms CWE-352
8.8
2018-05-12 CVE-2018-11003 Cross-Site Request Forgery (CSRF) vulnerability in Yxcms 1.4.7
An issue was discovered in YXcms 1.4.7.
network
low complexity
yxcms CWE-352
6.5
2018-05-11 CVE-2018-6458 Cross-Site Request Forgery (CSRF) vulnerability in Ehcp Easy Hosting Control Panel 0.37.12.B
Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
network
low complexity
ehcp CWE-352
8.8
2018-05-11 CVE-2018-6023 Cross-Site Request Forgery (CSRF) vulnerability in Fastweb Fastgate Firmware 0.00.47
Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc.
network
low complexity
fastweb CWE-352
8.8
2018-05-10 CVE-2018-10957 Cross-Site Request Forgery (CSRF) vulnerability in Dlink Dir-868L Firmware 1.12
CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password.
network
low complexity
dlink CWE-352
8.8
2018-05-05 CVE-2018-10758 Cross-Site Request Forgery (CSRF) vulnerability in Datenstrom Yellow 0.7.3
The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.
network
low complexity
datenstrom CWE-352
6.5
2018-05-03 CVE-2018-10166 Cross-Site Request Forgery (CSRF) vulnerability in Tp-Link EAP Controller 2.5.4/2.6.0
The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms.
network
low complexity
tp-link CWE-352
8.8
2018-05-01 CVE-2013-0185 Cross-Site Request Forgery (CSRF) vulnerability in Redhat Manageiq Enterprise Virtualization Manager
Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
network
low complexity
redhat CWE-352
8.8
2018-04-27 CVE-2018-10503 Cross-Site Request Forgery (CSRF) vulnerability in Baijiacms Project Baijiacms 41420170105
An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105.
network
low complexity
baijiacms-project CWE-352
8.8
2018-04-27 CVE-2018-1479 Cross-Site Request Forgery (CSRF) vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8