Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-07-18 CVE-2019-1010094 Cross-Site Request Forgery (CSRF) vulnerability in Domainmod 4.10.0
domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF).
network
domainmod CWE-352
6.8
2019-07-18 CVE-2019-1010054 Cross-Site Request Forgery (CSRF) vulnerability in Dolibarr Erp/Crm 7.0.0
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF).
network
low complexity
dolibarr CWE-352
8.8
2019-07-17 CVE-2019-10353 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.
network
high complexity
jenkins CWE-352
7.5
2019-07-16 CVE-2019-13611 Cross-Site Request Forgery (CSRF) vulnerability in Python-Engineio Project Python-Engineio
An issue was discovered in python-engineio through 3.8.2.
6.8
2019-07-14 CVE-2019-13594 Cross-Site Request Forgery (CSRF) vulnerability in Mirumee Saleor 2.7.0
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.
network
mirumee CWE-352
6.8
2019-07-11 CVE-2019-13563 Cross-Site Request Forgery (CSRF) vulnerability in Dlink Dir-655 Firmware 3.02B05
D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.
network
dlink CWE-352
6.8
2019-07-11 CVE-2019-12363 Cross-Site Request Forgery (CSRF) vulnerability in Mybb-2Fa Project Mybb-2Fa 20141105
An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB.
6.8
2019-07-11 CVE-2019-10340 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Docker
A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-352
8.8
2019-07-10 CVE-2019-12466 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Wikimedia MediaWiki through 1.32.1 allows CSRF.
6.8
2019-07-10 CVE-2019-13071 Cross-Site Request Forgery (CSRF) vulnerability in Cyberpowersystems Powerpanel 3.4.0
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application.
6.8