Total
4240 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-10253 | 1 Teammatesolutions | 1 Teammate\+ | 2019-09-10 | 4.3 MEDIUM | 6.5 MEDIUM |
A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists within the handling of Upload/DomainObjectDocumentUpload.ashx requests because of failure to validate a CSRF token before handling a POST request. | |||||
CVE-2017-18607 | 1 Theme-fusion | 1 Avada | 2019-09-10 | 6.8 MEDIUM | 8.8 HIGH |
The avada theme before 5.1.5 for WordPress has CSRF. | |||||
CVE-2019-16099 | 1 Silver-peak | 2 Unity Edgeconnect Sd-wan, Unity Edgeconnect Sd-wan Firmware | 2019-09-09 | 6.8 MEDIUM | 8.8 HIGH |
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file. | |||||
CVE-2019-15128 | 1 If.svnadmin Project | 1 If.svnadmin | 2019-09-09 | 4.3 MEDIUM | 6.5 MEDIUM |
iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user. | |||||
CVE-2019-16059 | 1 Sapplica | 1 Sentrifugo | 2019-09-08 | 6.8 MEDIUM | 8.8 HIGH |
Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/viewprofile via a crafted HTML page. | |||||
CVE-2018-17584 | 1 Wpfastestcache | 1 Wp Fastest Cache | 2019-09-06 | 6.8 MEDIUM | 8.8 HIGH |
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page. | |||||
CVE-2018-1000086 | 1 Npr | 1 Pym.js | 2019-09-06 | 6.8 MEDIUM | 8.8 HIGH |
NPR Visuals Team Pym.js version versions 0.4.2 up to 1.3.1 contains a Cross ite Request Forgery (CSRF) vulnerability in Pym.js _onNavigateToMessage function. https://github.com/nprapps/pym.js/blob/master/src/pym.js#L573 that can result in Arbitrary javascript code execution. This attack appear to be exploitable via Attacker gains full javascript access to pages with Pym.js embeds when user visits an attacker crafted page.. This vulnerability appears to have been fixed in versions 1.3.2 and later. | |||||
CVE-2019-15828 | 1 Tribulant | 1 One Click Ssl | 2019-09-05 | 6.8 MEDIUM | 8.8 HIGH |
The one-click-ssl plugin before 1.4.7 for WordPress has CSRF. | |||||
CVE-2019-15769 | 1 Haktansuren | 1 Handl Utm Grabber | 2019-09-05 | 6.8 MEDIUM | 8.8 HIGH |
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option. | |||||
CVE-2019-15835 | 1 Wp Better Permalinks Project | 1 Wp Better Permalinks | 2019-09-04 | 6.8 MEDIUM | 8.8 HIGH |
The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF. | |||||
CVE-2019-15770 | 1 Hallme | 1 Woocommerce Address Book | 2019-09-04 | 6.8 MEDIUM | 8.8 HIGH |
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks. | |||||
CVE-2019-15834 | 1 Webp Converter For Media Project | 1 Webp Converter For Media | 2019-09-04 | 6.8 MEDIUM | 8.8 HIGH |
The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF. | |||||
CVE-2019-15779 | 1 Quadlayers | 1 Wp Social Feed Gallery | 2019-09-03 | 6.8 MEDIUM | 8.8 HIGH |
The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete. | |||||
CVE-2019-15841 | 1 Facebook | 1 Facebook For Woocommerce | 2019-09-03 | 6.8 MEDIUM | 8.8 HIGH |
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility. | |||||
CVE-2019-15868 | 1 Wpaffiliatemanager | 1 Affiliates Manager | 2019-09-03 | 6.8 MEDIUM | 8.8 HIGH |
The affiliates-manager plugin before 2.6.6 for WordPress has CSRF. | |||||
CVE-2019-15831 | 1 Wp-buy | 1 Visitor Traffic Real Time Statistics | 2019-09-03 | 6.8 MEDIUM | 8.8 HIGH |
The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page. | |||||
CVE-2019-15832 | 1 Wp-buy | 1 Visitor Traffic Real Time Statistics | 2019-09-03 | 6.8 MEDIUM | 8.8 HIGH |
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF. | |||||
CVE-2015-9380 | 1 10web | 1 Photo Gallery | 2019-09-03 | 6.8 MEDIUM | 8.8 HIGH |
The photo-gallery plugin before 1.2.42 for WordPress has CSRF. | |||||
CVE-2019-15865 | 1 Holest | 1 Breadcrumbs By Menu | 2019-09-03 | 6.8 MEDIUM | 8.8 HIGH |
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF. | |||||
CVE-2019-15840 | 1 Facebook | 1 Facebook For Woocommerce | 2019-09-03 | 6.8 MEDIUM | 8.8 HIGH |
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF. |