Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Phpmyfaq HIGH 8.8
CVE-2017-15732

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15733

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15734

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15735

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Webmin HIGH 8.8
CVE-2017-15645

CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary command…

Fix: after 1.850
Fix from $1,950 2017-10-19
Spa300 Firmware HIGH 8.8
CVE-2017-12271

A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affecte…

Fix: after 7.5.5
Fix from $1,950 2017-10-19
Realtyna Property Listing HIGH 8.8
CVE-2015-7715

Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack th…

Fix: 8.9.5+
Fix from $1,950 2017-10-18
Unified Security Management MEDIUM 5.7
CVE-2017-14956

AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php…

Fix: after 5.4.2
Fix from $1,600 2017-10-18
Keycloak HIGH 8.8
CVE-2014-3709

The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site…

Fix: after 1.0.2.final
Fix from $1,950 2017-10-18
Multiflex M10a Controller Firmware HIGH 8.8
CVE-2017-14011

A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify …

Mitigation only
Fix from $1,950 2017-10-17
Customer Relationship Management HIGH 8.8
CVE-2017-15296

The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.

No fix yet
Fix from $1,950 2017-10-16
Junos HIGH 8.8
CVE-2016-1261

J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS).

Mitigation only
Fix from $1,950 2017-10-13
Junos Space CRITICAL 9.8
CVE-2016-1265

A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices manage…

Fix: after 15.1r2
Fix from $2,300 2017-10-13
Jtc 200 Firmware HIGH 8.0
CVE-2016-5789

A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions. An attacker could perform actions with the same permissions as a v…

Mitigation only
Fix from $1,950 2017-10-13
Phpbugtracker HIGH 8.0
CVE-2015-2142

Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack …

Fix: after 1.6.0
Fix from $1,950 2017-10-06
Phpbugtracker HIGH 8.8
CVE-2015-2143

Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentica…

Fix: after 1.6.0
Fix from $1,950 2017-10-06
Metasploit MEDIUM 6.5
CVE-2017-15084

The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.

Fix: after 4.14.1
Fix from $1,600 2017-10-06
Subrion HIGH 8.8
CVE-2017-15063

There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to det…

Fix: after 4.1.5
Fix from $1,950 2017-10-06
Subversion MEDIUM 6.5
CVE-2017-1000085

Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality…

Fix: after 2.8
Fix from $1,600 2017-10-05
Role Based Authorization Strategy HIGH 8.8
CVE-2017-1000090

Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery…

Fix: after 2.5.0
Fix from $1,950 2017-10-05
Github Branch Source MEDIUM 6.3
CVE-2017-1000091

GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to v…

Mitigation only
Fix from $1,600 2017-10-05
Git HIGH 7.5
CVE-2017-1000092

Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at …

Mitigation only
Fix from $1,950 2017-10-05
Poll Scm HIGH 8.8
CVE-2017-1000093

Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed at…

Fix: after 1.3.1
Fix from $1,950 2017-10-05
Wicket HIGH 8.8
CVE-2016-6806

Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. …

Mitigation only
Fix from $1,950 2017-10-03
Tikiwiki Cms\/groupware HIGH 8.0
CVE-2017-14924

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.…

Patch available
Fix from $1,950 2017-09-30
Tikiwiki Cms\/groupware HIGH 8.0
CVE-2017-14925

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.…

Patch available
Fix from $1,950 2017-09-30
Cp Contact Form With Paypal HIGH 8.8
CVE-2015-9233

The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contac…

Fix: 1.1.6+
Fix from $1,950 2017-09-30
Zktime Web HIGH 8.0
CVE-2017-13129

Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of ad…

Mitigation only
Fix from $1,950 2017-09-26
Powerscada Anywhere HIGH 8.8
CVE-2017-7969

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with…

Patch available
Fix from $1,950 2017-09-26
Amq HIGH 8.8
CVE-2015-5182

Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.

Mitigation only
Fix from $1,950 2017-09-25