Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-05-15 CVE-2017-2613 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins
jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins.
network
low complexity
jenkins CWE-352
5.4
2018-05-15 CVE-2018-11127 Cross-Site Request Forgery (CSRF) vulnerability in E107 2.1.7
e107 2.1.7 has CSRF resulting in arbitrary user deletion.
network
low complexity
e107 CWE-352
6.5
2018-05-15 CVE-2018-11126 Cross-Site Request Forgery (CSRF) vulnerability in Doorgets 7.0
dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account.
network
low complexity
doorgets CWE-352
8.8
2018-05-14 CVE-2017-12126 Cross-Site Request Forgery (CSRF) vulnerability in Moxa Edr-810 Firmware 4.1
An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317.
network
low complexity
moxa CWE-352
8.8
2018-05-13 CVE-2018-11018 Cross-Site Request Forgery (CSRF) vulnerability in Pbootcms 1.0.7
An issue was discovered in PbootCMS v1.0.7.
network
low complexity
pbootcms CWE-352
8.8
2018-05-12 CVE-2018-11004 Cross-Site Request Forgery (CSRF) vulnerability in Sdcms 1.5
An issue was discovered in SDcms v1.5.
network
low complexity
sdcms CWE-352
8.8
2018-05-12 CVE-2018-11003 Cross-Site Request Forgery (CSRF) vulnerability in Yxcms 1.4.7
An issue was discovered in YXcms 1.4.7.
network
low complexity
yxcms CWE-352
6.5
2018-05-11 CVE-2018-6458 Cross-Site Request Forgery (CSRF) vulnerability in Ehcp Easy Hosting Control Panel 0.37.12.B
Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
network
low complexity
ehcp CWE-352
8.8
2018-05-11 CVE-2018-6023 Cross-Site Request Forgery (CSRF) vulnerability in Fastweb Fastgate Firmware 0.00.47
Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc.
network
low complexity
fastweb CWE-352
8.8
2018-05-10 CVE-2018-10957 Cross-Site Request Forgery (CSRF) vulnerability in Dlink Dir-868L Firmware 1.12
CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password.
network
low complexity
dlink CWE-352
8.8