Export limit exceeded: 10027 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10027 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2017-18511 | 1 Wpmudev | 1 Custom Sidebars | 2024-11-21 | N/A |
| The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF. | ||||
| CVE-2017-18510 | 1 Wpmudev | 1 Custom Sidebars | 2024-11-21 | N/A |
| The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions. | ||||
| CVE-2017-18504 | 1 Wpdeveloper | 1 Twitter Cards Meta | 2024-11-21 | N/A |
| The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF. | ||||
| CVE-2017-18485 | 1 Elementalpath | 2 Cognitoys Dino, Cognitoys Dino Firmware | 2024-11-21 | N/A |
| Cognitoys Dino devices allow profiles_add.html CSRF. | ||||
| CVE-2017-18366 | 1 Intelliants | 1 Subrion Cms | 2024-11-21 | N/A |
| Subrion CMS 4.1.5 has CSRF in blog/delete/. | ||||
| CVE-2017-18107 | 1 Atlassian | 1 Crowd | 2024-11-21 | 6.5 Medium |
| Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default. | ||||
| CVE-2017-18080 | 1 Atlassian | 1 Bamboo | 2024-11-21 | N/A |
| The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability. | ||||
| CVE-2017-18042 | 1 Atlassian | 1 Bamboo | 2024-11-21 | N/A |
| The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability. | ||||
| CVE-2017-18033 | 1 Atlassian | 1 Jira | 2024-11-21 | N/A |
| The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities. | ||||
| CVE-2017-17835 | 1 Apache | 1 Airflow | 2024-11-21 | N/A |
| In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow. | ||||
| CVE-2017-17550 | 1 Zyxel | 2 Zywall Usg 100, Zywall Usg 100 Firmware | 2024-11-21 | N/A |
| ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS. | ||||
| CVE-2017-16886 | 1 Fiberhome | 2 Lm53q1, Lm53q1 Firmware | 2024-11-21 | N/A |
| The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal. | ||||
| CVE-2017-16862 | 1 Atlassian | 1 Jira | 2024-11-21 | N/A |
| The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability. | ||||
| CVE-2017-16769 | 1 Synology | 1 Photo Station | 2024-11-21 | N/A |
| Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode. | ||||
| CVE-2017-16756 | 1 Userscape | 1 Helpspot | 2024-11-21 | N/A |
| An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account. | ||||
| CVE-2017-15706 | 1 Apache | 1 Tomcat | 2024-11-21 | N/A |
| As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. Note that the behaviour of the CGI servlet has remained unchanged in this regard. It is only the documentation of the behaviour that was wrong and has been corrected. | ||||
| CVE-2017-15665 | 1 Flexense | 1 Diskboss | 2024-11-21 | N/A |
| In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094. | ||||
| CVE-2017-15664 | 1 Flexense | 1 Syncbreeze | 2024-11-21 | N/A |
| In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9121. | ||||
| CVE-2017-15663 | 1 Flexense | 1 Disk Pulse | 2024-11-21 | N/A |
| In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120. | ||||
| CVE-2017-15662 | 1 Flexense | 1 Vx Search | 2024-11-21 | N/A |
| In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9123. | ||||