Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-02-05 CVE-2018-6651 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions.
network
low complexity
uncurl-project parsecgaming CWE-352
8.8
2018-02-05 CVE-2017-9414 Cross-Site Request Forgery (CSRF) vulnerability in Subsonic 6.1.1
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that conduct cross-site scripting (XSS) attacks or possibly have unspecified other impact via the name parameter to playerSettings.view.
network
low complexity
subsonic CWE-352
8.8
2018-02-05 CVE-2015-4179 Cross-Site Request Forgery (CSRF) vulnerability in Codestyling Localization Project Codestyling Localization
Multiple cross-site request forgery (CSRF) vulnerabilities in the Codestyling Localization plugin 1.99.30 and earlier for Wordpress.
network
low complexity
codestyling-localization-project CWE-352
8.8
2018-02-02 CVE-2017-18080 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Bamboo
The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.
network
low complexity
atlassian CWE-352
8.8
2018-02-02 CVE-2017-18042 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Bamboo
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
network
low complexity
atlassian CWE-352
8.8
2018-02-01 CVE-2014-9502 Cross-Site Request Forgery (CSRF) vulnerability in Open Atrium Project Open Atrium
Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified sub modules in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allow remote attackers to hijack the authentication of unknown victims via vectors related to menu callbacks.
network
low complexity
open-atrium-project CWE-352
8.8
2018-02-01 CVE-2018-0509 Cross-Site Request Forgery (CSRF) vulnerability in Kkcald Project Kkcald 0.7.19/0.7.21
Cross-site request forgery (CSRF) vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attacker to hijack the authentication of administrators via unspecified vectors.
network
low complexity
kkcald-project CWE-352
8.8
2018-01-30 CVE-2018-6408 Cross-Site Request Forgery (CSRF) vulnerability in Conceptronic Cipcamptiwl Firmware and Cipcamptiwl web Firmware
An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices.
network
low complexity
conceptronic CWE-352
8.8
2018-01-29 CVE-2018-6391 Cross-Site Request Forgery (CSRF) vulnerability in Netis-Systems Wf2419 Firmware 2.2.36123
A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices.
network
low complexity
netis-systems CWE-352
8.8
2018-01-29 CVE-2017-1000356 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: create an account if signup is enabled; or create an account if the victim is an administrator, possibly deleting the existing default admin user in the process and allowing a wide variety of impacts.
network
low complexity
jenkins CWE-352
8.8