Search Results (9235 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2016-6578 1 Filecloud 1 Filecloud 2024-11-21 8.8 High
CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.
CVE-2016-6557 1 Asus 14 Ea-n66, Ea-n66 Firmware, Rp-ac52 and 11 more 2024-11-21 N/A
In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.
CVE-2016-3098 1 Thoughtbot 1 Administrate 2024-11-21 5.4 Medium
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.
CVE-2016-15028 1 Icepay 1 Rest Api 2024-11-21 4.8 Medium
A vulnerability was found in ICEPAY REST-API-NET 0.9. It has been declared as problematic. Affected by this vulnerability is the function RestClient of the file Classes/RestClient.cs of the component Checksum Validation. The manipulation leads to improper validation of integrity check value. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 1.0 is able to address this issue. The patch is named 61f6b8758e5c971abff5f901cfa9f231052b775f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-222847.
CVE-2016-11085 1 Expresstech 1 Quiz And Survey Master 2024-11-21 6.5 Medium
php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.
CVE-2016-11084 1 Mattermost 1 Mattermost Server 2024-11-21 6.1 Medium
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
CVE-2016-11055 1 Netgear 26 Cm400, Cm400 Firmware, Cm600 and 23 more 2024-11-21 4.3 Medium
Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 before 2017-01-11, JWNR2000Tv3 before 2017-01-11, JWNR2010v3 before 2017-01-11, PLW1000 before 2017-01-11, PLW1010 before 2017-01-11, WNR500 before 2017-01-11, WNR612v3 before 2017-01-11, N450 before 2017-01-11, and CG3000Dv2 before 2017-01-11.
CVE-2016-11015 1 Netgear 2 Jnr1010, Jnr1010 Firmware 2024-11-21 6.5 Medium
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
CVE-2016-10997 1 Yourinspirationweb 1 Beauty-premium 2024-11-21 6.5 Medium
The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.
CVE-2016-10989 1 Leenk 1 Leenk.me 2024-11-21 8.8 High
The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.
CVE-2016-10982 1 Kentothemes 1 Kento-post-view-counter 2024-11-21 8.8 High
The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.
CVE-2016-10978 1 Fossura 1 Tag Miner 2024-11-21 8.8 High
The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.
CVE-2016-10974 1 Tonjoostudio 1 Fluid-responsive-slideshow 2024-11-21 8.8 High
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.
CVE-2016-10962 1 Icegram 1 Icegram Engage 2024-11-21 6.5 Medium
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
CVE-2016-10946 1 Wp-d3 Project 1 Wp-d3 2024-11-21 8.8 High
The wp-d3 plugin before 2.4.1 for WordPress has CSRF.
CVE-2016-10945 1 Pagelines 1 Pagelines 2024-11-21 8.8 High
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
CVE-2016-10944 1 Wpmaz 1 Multisite Post Duplicator 2024-11-21 8.8 High
The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
CVE-2016-10938 1 Copy-me Project 1 Copy-me 2024-11-21 6.5 Medium
The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.
CVE-2016-10918 1 Supsystic 1 Photo Gallery 2024-11-21 N/A
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
CVE-2016-10915 1 Supsystic 1 Popup 2024-11-21 N/A
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.