Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Plone HIGH 8.8
CVE-2015-7293

Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.

Fix: after 4.3.7
Fix from $1,950 2017-09-25
Geminabox HIGH 8.8
CVE-2017-14683

geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.

Fix: after 0.13.6
Fix from $1,950 2017-09-25
Kallithea HIGH 8.8
CVE-2015-0276

Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2.

Fix: after 0.1
Fix from $1,950 2017-09-21
Unified Intelligence Center HIGH 8.8
CVE-2017-12253

A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerabili…

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux HIGH 8.8
CVE-2015-5395

Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.

Fix: 3.1.0+
Fix from $1,950 2017-09-20
Fedora HIGH 8.8
CVE-2015-5607

Cross-site request forgery in the REST API in IPython 2 and 3.

Patch available
Fix from $1,950 2017-09-20
Wp Fastest Cache HIGH 8.8
CVE-2015-4089

Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 …

Fix: after 0.8.3.4
Fix from $1,950 2017-09-19
Security Identity Manager HIGH 8.8
CVE-2014-6106

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authenticati…

Patch available
Fix from $1,950 2017-09-18
Crony Cronjob Manager HIGH 8.0
CVE-2017-14530

WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, a…

Fix: after 0.4.6
Fix from $1,950 2017-09-18
Brooklyn HIGH 8.8
CVE-2016-8737

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to prod…

Fix: after 0.9.0
Fix from $1,950 2017-09-13
Mu553s Firmware HIGH 8.8
CVE-2017-11350

Cross-Site Request Forgery (CSRF) exists in cgi-bin/ConfigSet on Axesstel MU553S MU55XS-V1.14 devices.

Mitigation only
Fix from $1,950 2017-09-13
4gee Wifi Mbb Firmware HIGH 8.8
CVE-2017-14267

EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have CSRF, related to goform/AddNewProfile, goform/setWanDisconnect, goform/setSMSAutoRedirectSett…

No fix yet
Fix from $1,950 2017-09-11
Ib6131 Firmware HIGH 8.8
CVE-2014-9565

Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earli…

Fix: after 3.4.0.0.0.0
Fix from $1,950 2017-09-07
Spina HIGH 8.8
CVE-2015-4619

Cross-site request forgery (CSRF) vulnerability in Spina before commit bfe44f289e336f80b6593032679300c493735e75.

Fix: after 0.11.1
Fix from $1,950 2017-09-07
Google Analyticator HIGH 8.8
CVE-2015-4697

Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.

Fix: after 6.4.9.3
Fix from $1,950 2017-09-07
Mongoose Embedded Web Server Library HIGH 8.8
CVE-2017-11567

Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for r…

Fix: after 6.8
Fix from $1,950 2017-09-07
Nexusphp HIGH 8.8
CVE-2017-12838

Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) s…

No fix yet
Fix from $1,950 2017-09-07
Emptoris Strategic Supply Management HIGH 8.8
CVE-2017-1097

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site request forgery which could allow an attacker…

Mitigation only
Fix from $1,950 2017-09-05
Blackcat Cms HIGH 8.8
CVE-2017-14048

BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addon…

Mitigation only
Fix from $1,950 2017-08-31
Emptoris Services Procurement HIGH 8.8
CVE-2017-1442

IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unautho…

Patch available
Fix from $1,950 2017-08-30
Sametime MEDIUM 6.5
CVE-2016-0355

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 6.5
CVE-2016-0356

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 6.5
CVE-2016-2965

IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persu…

Patch available
Fix from $1,600 2017-08-29
Clearpass HIGH 8.8
CVE-2015-3655

Cross-site request forgery (CSRF) vulnerability in Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attacker…

Fix: 6.4.7 / 6.5.2+
Fix from $1,950 2017-08-29
Connect Secure HIGH 8.8
CVE-2017-11455

diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R…

Mitigation only
Fix from $1,950 2017-08-29
Urbancode Deploy HIGH 8.8
CVE-2014-8900

Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.

Fix: after 6.1.1.1
Fix from $1,950 2017-08-28
Pi Web Api HIGH 8.8
CVE-2017-7926

A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request f…

Mitigation only
Fix from $1,950 2017-08-25
Mrd 305 Din Firmware HIGH 8.8
CVE-2017-12703

A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions …

Mitigation only
Fix from $1,950 2017-08-25
Apache2triad HIGH 8.8
CVE-2017-12970

Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for…

No fix yet
Fix from $1,950 2017-08-23
Fedora HIGH 8.8
CVE-2015-5258

Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.

Fix: 1.1.3+
Fix from $1,950 2017-08-22