Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Dnsdist HIGH 8.8
CVE-2017-7557

dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.

Patch available
Fix from $1,950 2017-08-22
Directory Server HIGH 8.8
CVE-2017-5187

A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Deve…

Fix: after 2.3
Fix from $1,950 2017-08-21
Enterprise Developer HIGH 8.8
CVE-2017-7423

A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 befor…

Mitigation only
Fix from $1,950 2017-08-21
Spring Batch Admin HIGH 8.8
CVE-2017-12881

Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin before 1.3.0 allows remote attackers to hijack the authentication of unspec…

Fix: after 1.2.1
Fix from $1,950 2017-08-18
Django Cms HIGH 8.8
CVE-2015-5081

Cross-site request forgery (CSRF) vulnerability in django CMS before 3.0.14, 3.1.x before 3.1.1 allows remote attackers to manipulate privileged user…

Fix: after 3.0.13
Fix from $1,950 2017-08-18
R60g Firmware HIGH 8.8
CVE-2017-12589

ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.

No fix yet
Fix from $1,950 2017-08-18
Dsl N10s Firmware HIGH 8.8
CVE-2017-12593

ASUS DSL-N10S V2.1.16_APAC devices allow CSRF.

No fix yet
Fix from $1,950 2017-08-18
Hawtio HIGH 8.8
CVE-2017-7556

Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website con…

Mitigation only
Fix from $1,950 2017-08-17
Rwr 3g 100 Firmware HIGH 8.8
CVE-2017-12853

The RealTime RWR-3G-100 Router Firmware Version : Ver1.0.56 is affected by CSRF an attack that forces an end user to execute unwanted actions on a we…

No fix yet
Fix from $1,950 2017-08-14
Message Gateway HIGH 8.8
CVE-2017-6328

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbrevia…

Fix: after 10.6.3-2
Fix from $1,950 2017-08-11
Loginizer HIGH 8.8
CVE-2017-12651

Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress beca…

Fix: after 1.3.5
Fix from $1,950 2017-08-07
Prime Collaboration Provisioning HIGH 8.8
CVE-2017-6756

A vulnerability in the Web UI Application of the Cisco Prime Collaboration Provisioning Tool through 12.2 could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,950 2017-08-07
Ea4500 Firmware HIGH 8.8
CVE-2017-10677

Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.…

Fix: after 2.0.36
Fix from $1,950 2017-08-06
Senayan Library Management System HIGH 8.8
CVE-2017-12584

There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the…

Fix: after 8.3.1
Fix from $1,950 2017-08-06
Sunny Boy 3600 Firmware HIGH 8.8
CVE-2017-9863

An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site…

Mitigation only
Fix from $1,950 2017-08-05
Flash Slideshow Maker HIGH 7.5
CVE-2017-12439

SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-s…

Fix: after 5.20
Fix from $1,950 2017-08-05
Cs Cart HIGH 8.8
CVE-2017-2138

Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese E…

Fix: after 4.3.10
Fix from $1,950 2017-08-02
Tr 1803 3g Firmware HIGH 8.8
CVE-2017-11648

Techroutes TR 1803-3G Wireless Cellular Router/Modem 2.4.25 devices do not possess any protection against a CSRF vulnerability, as demonstrated by a …

Mitigation only
Fix from $1,950 2017-07-31
Manage HIGH 8.8
CVE-2017-11726

services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrated by c…

No fix yet
Fix from $1,950 2017-07-31
Infosphere Master Data Management Server HIGH 8.8
CVE-2016-9714

IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an …

Patch available
Fix from $1,950 2017-07-31
Infosphere Master Data Management Server HIGH 8.8
CVE-2016-9716

IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attack…

Patch available
Fix from $1,950 2017-07-31
Dpc3939b Firmware HIGH 8.8
CVE-2017-9489

The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF.

No fix yet
Fix from $1,950 2017-07-31
Dpc3939b Firmware HIGH 8.8
CVE-2017-9490

The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows configurati…

No fix yet
Fix from $1,950 2017-07-31
4gt101w Software HIGH 8.8
CVE-2017-11646

NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by usin…

Mitigation only
Fix from $1,950 2017-07-28
Hashtopus HIGH 8.8
CVE-2017-11679

Cross-Site Request Forgery (CSRF) exists in Hashtopus 1.5g via the password parameter to admin.php in an a=config action.

No fix yet
Fix from $1,950 2017-07-27
Hashtopussy HIGH 8.8
CVE-2017-11680

Cross-Site Request Forgery (CSRF) exists in Hashtopussy 0.4.0, allowing an admin password change via users.php.

Fix: after 0.4.0
Fix from $1,950 2017-07-27
Subsonic HIGH 8.8
CVE-2017-9413

Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authenticati…

No fix yet
Fix from $1,950 2017-07-25
Wmr 433 Firmware HIGH 8.8
CVE-2017-2273

Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attack…

Fix: after 1.40
Fix from $1,950 2017-07-22
Subsonic HIGH 7.5
CVE-2017-9415

Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authent…

No fix yet
Fix from $1,950 2017-07-21
Koha HIGH 8.8
CVE-2015-4639

Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 …

Mitigation only
Fix from $1,950 2017-07-21