Total
6084 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-6288 | 1 Kaspersky | 1 Secure Mail Gateway | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1. | |||||
CVE-2018-6224 | 1 Trendmicro | 1 Email Encryption Gateway | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit authenticated requests to a user browsing an attacker-controlled domain. | |||||
CVE-2018-6023 | 1 Fastweb | 2 Fastgate, Fastgate Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc. | |||||
CVE-2018-6009 | 1 Yiiframework | 1 Yiiframework | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity. | |||||
CVE-2018-6007 | 1 Joomsky | 1 Js Support Ticket | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket. | |||||
CVE-2018-5976 | 1 Rsvp Invitation Online Project | 1 Rsvp Invitation Online | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin password. | |||||
CVE-2018-5969 | 1 Photography Cms Project | 1 Photography Cms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demonstrated by adding an admin account. | |||||
CVE-2018-5921 | 1 Hp | 387 A2w75a, A2w75a Firmware, A2w76a and 384 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions. This vulnerability is known as Cross Site Request Forgery, and could potentially be exploited remotely to allow elevation of privilege. | |||||
CVE-2018-5720 | 1 Dodocool | 2 Dc38, Dc38 Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A Cross-site request forgery (CSRF) vulnerability allows remote attackers to hijack the authentication of users for requests that modify all the settings. This vulnerability can lead to changing an existing user's username and password, changing the Wi-Fi password, etc. | |||||
CVE-2018-5673 | 1 Booking Calendar Project | 1 Booking Calendar | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php. | |||||
CVE-2018-5669 | 1 Read And Understood Project | 1 Read And Understood | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.php. | |||||
CVE-2018-5658 | 1 Responsive Coming Soon Page Project | 1 Responsive Coming Soon Page | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php. | |||||
CVE-2018-5656 | 1 Weblizar | 1 Pinterest-feeds | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php. | |||||
CVE-2018-5368 | 1 Srbtranslatin Project | 1 Srbtranslatin | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php. | |||||
CVE-2018-5361 | 1 Wpglobus | 1 Wpglobus | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php. | |||||
CVE-2018-5329 | 1 Beims | 1 Contractorweb.net | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application. | |||||
CVE-2018-5301 | 1 Magento | 1 Magento | 2024-11-21 | 5.8 MEDIUM | 6.5 MEDIUM |
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433. | |||||
CVE-2018-5285 | 1 Wpscoop | 1 Imageinject | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php. | |||||
CVE-2018-5123 | 1 Mozilla | 1 Bugzilla | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4.4. | |||||
CVE-2018-5073 | 1 Advanced Real Estate Script Project | 1 Advanced Real Estate Script | 2024-11-21 | 6.0 MEDIUM | 6.8 MEDIUM |
Online Ticket Booking has CSRF via admin/movieedit.php. |