Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-02-04 CVE-2019-1000003 Cross-Site Request Forgery (CSRF) vulnerability in Mapsvg Lite 3.2.3
MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embedding javascript.
network
mapsvg CWE-352
6.8
2019-02-04 CVE-2019-7346 Cross-Site Request Forgery (CSRF) vulnerability in Zoneminder
A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.
6.8
2019-02-01 CVE-2019-3604 Cross-Site Request Forgery (CSRF) vulnerability in Mcafee Epolicy Orchestrator
Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user's session via unspecified vectors.
network
low complexity
mcafee CWE-352
8.8
2019-01-24 CVE-2019-6779 Cross-Site Request Forgery (CSRF) vulnerability in Chshcms Cscms 4.1.8
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.
network
chshcms CWE-352
5.8
2019-01-24 CVE-2019-1658 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 11.6(1)
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.
network
cisco CWE-352
4.3
2019-01-23 CVE-2017-17835 Cross-Site Request Forgery (CSRF) vulnerability in Apache Airflow
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
network
low complexity
apache CWE-352
8.8
2019-01-22 CVE-2019-6510 Cross-Site Request Forgery (CSRF) vulnerability in Creditease-Sec Insight
An issue was discovered in creditease-sec insight through 2018-09-11.
6.8
2019-01-22 CVE-2019-6509 Cross-Site Request Forgery (CSRF) vulnerability in Creditease-Sec Insight
An issue was discovered in creditease-sec insight through 2018-09-11.
6.8
2019-01-22 CVE-2019-6508 Cross-Site Request Forgery (CSRF) vulnerability in Creditease-Sec Insight
An issue was discovered in creditease-sec insight through 2018-09-11.
6.8
2019-01-22 CVE-2019-6507 Cross-Site Request Forgery (CSRF) vulnerability in Creditease-Sec Insight
An issue was discovered in creditease-sec insight through 2018-09-11.
6.8