Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Jazz For Service Management HIGH 8.8
CVE-2017-1631

IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute ma…

Patch available
Fix from $1,950 2017-12-20
Jazz For Service Management HIGH 8.8
CVE-2017-1746

IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute ma…

Patch available
Fix from $1,950 2017-12-20
Piwigo HIGH 8.8
CVE-2017-17774

admin/configuration.php in Piwigo 2.9.2 has CSRF.

Patch available
Fix from $1,950 2017-12-20
Scanmail HIGH 8.8
CVE-2017-14092

The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated request…

Patch available
Fix from $1,950 2017-12-16
Nexpose HIGH 8.8
CVE-2017-5264

Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web app…

Fix: 6.4.66+
Fix from $1,950 2017-12-14
Project And Portfolio Management HIGH 7.3
CVE-2017-14362

Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited …

Mitigation only
Fix from $1,950 2017-12-13
Zktime Web HIGH 8.8
CVE-2017-17056

The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function o…

No fix yet
Fix from $1,950 2017-12-04
Cxf Fediz HIGH 8.8
CVE-2017-12631

Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty…

Fix: 1.3.3+
Fix from $1,950 2017-11-30
Pentaho Business Analytics HIGH 8.8
CVE-2016-10701

In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application.

Fix: after 8.0
Fix from $1,950 2017-11-28
Hedex Lite HIGH 8.8
CVE-2017-8138

HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a websit…

Mitigation only
Fix from $1,950 2017-11-22
Vcenter Server HIGH 7.5
CVE-2017-4928

The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRL…

Patch available
Fix from $1,950 2017-11-17
Youtube MEDIUM 6.5
CVE-2017-1000224

CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin

Fix: after 11.8.1
Fix from $1,600 2017-11-17
Snapcenter Server HIGH 8.8
CVE-2017-15516

NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause a…

Patch available
Fix from $1,950 2017-11-16
Dcs 936l HIGH 8.8
CVE-2017-7851

D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a subst…

Fix: 1.05.07+
Fix from $1,950 2017-11-15
Project Server HIGH 8.8
CVE-2017-11876

Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are no…

Patch available
Fix from $1,950 2017-11-15
Mybb CRITICAL 9.8
CVE-2017-16780EPSS 6%

The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.

Fix: after 1.8.12
Fix from $2,300 2017-11-10
Ht802 Firmware HIGH 8.0
CVE-2017-16563

Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to …

No fix yet
Fix from $1,950 2017-11-06
Ht802 Firmware HIGH 8.8
CVE-2017-16565

Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login scree…

No fix yet
Fix from $1,950 2017-11-06
Keystone HIGH 8.8
CVE-2017-16570

KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_…

Fix: 4.0.0+
Fix from $1,950 2017-11-06
Mahara MEDIUM 6.8
CVE-2017-1000147

Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the u…

Patch available
Fix from $1,600 2017-11-03
Openpages Grc Platform HIGH 8.8
CVE-2017-1300

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2017-11-01
Favorite HIGH 8.8
CVE-2017-1000244

Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification

Fix: after 2.2.0
Fix from $1,950 2017-11-01
October HIGH 8.8
CVE-2017-16244

Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an …

Patch available
Fix from $1,950 2017-11-01
Cf Release HIGH 8.8
CVE-2015-5170

Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to…

Fix: 1.7.0 / 2.5.2+
Fix from $1,950 2017-10-24
Letodms HIGH 8.8
CVE-2012-4568

Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to hijack the authenticati…

Fix: after 3.3.7
Fix from $1,950 2017-10-23
Hawkeye G HIGH 8.8
CVE-2015-2878

Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of admin…

No fix yet
Fix from $1,950 2017-10-23
Phpmyfaq HIGH 8.8
CVE-2017-15808

In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-23
Phpmyfaq HIGH 8.8
CVE-2017-15729

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15730

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15731

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-22