Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Dx 350 Firmware HIGH 8.8
CVE-2017-9930

Cross-Site Request Forgery (CSRF) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by a request to ajax.cgi tha…

No fix yet
Fix from $1,950 2017-07-21
Bigfix Platform HIGH 8.8
CVE-2017-1218

IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions t…

Mitigation only
Fix from $1,950 2017-07-19
Glpi HIGH 8.0
CVE-2016-7507

Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creat…

Mitigation only
Fix from $1,950 2017-07-19
Redcap HIGH 8.8
CVE-2017-10961

REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.

Fix: after 7.5.0
Fix from $1,950 2017-07-18
Anti Virus For Linux Server HIGH 8.8
CVE-2017-9810

There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix …

Fix: after 8.0.3.297
Fix from $1,950 2017-07-17
Openmeetings HIGH 8.8
CVE-2017-7666

Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.

Mitigation only
Fix from $1,950 2017-07-17
Oauth2 Proxy HIGH 8.8
CVE-2017-1000069

CSRF in Bitly oauth2_proxy 2.1 during authentication flow

Patch available
Fix from $1,950 2017-07-17
Chyrp Lite HIGH 8.8
CVE-2017-1000008

Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users t…

Patch available
Fix from $1,950 2017-07-17
Pulse Connect Secure HIGH 8.8
CVE-2017-11193

Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute,…

Mitigation only
Fix from $1,950 2017-07-12
Pulse Connect Secure HIGH 8.8
CVE-2017-11196

Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attac…

Mitigation only
Fix from $1,950 2017-07-12
Hem Gw16a Firmware HIGH 8.8
CVE-2017-2238

Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway H…

Fix: after 1.2.0
Fix from $1,950 2017-07-07
Mfc J960dwn Firmware HIGH 8.8
CVE-2017-2244

Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of adm…

Mitigation only
Fix from $1,950 2017-07-07
Ts Wptcam Camera Firmware HIGH 8.8
CVE-2017-2223

Cross-site request forgery (CSRF) vulnerability in TS-WPTCAM, TS-PTCAM, TS-PTCAM/POE, TS-WLC2, TS-WLCE, TS-WRLC firmware version 1.19 and earlier and…

Fix: after 1.19
Fix from $1,950 2017-07-07
Dir 615 HIGH 8.8
CVE-2017-7404

On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the m…

Fix: after 20.12ptb01
Fix from $1,950 2017-07-07
Rsa Archer Egrc HIGH 8.8
CVE-2017-4998

EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is potentially affected by a cross-site request forgery vulnerability. A remote l…

Mitigation only
Fix from $1,950 2017-07-07
Request Tracker HIGH 8.8
CVE-2017-5943

Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cro…

Mitigation only
Fix from $1,950 2017-07-03
Gecko Lite Managed Switch Firmware HIGH 7.1
CVE-2017-6038

A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web applicat…

Fix: after 2.0.00
Fix from $1,950 2017-06-30
Airlink Raven Xe Firmware HIGH 8.8
CVE-2017-6042

A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versio…

Mitigation only
Fix from $1,950 2017-06-30
Piwigo HIGH 8.8
CVE-2017-10678

Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to…

Fix: after 2.9.1
Fix from $1,950 2017-06-29
Piwigo HIGH 8.8
CVE-2017-10680

Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to…

Fix: after 2.9.1
Fix from $1,950 2017-06-29
Piwigo HIGH 8.8
CVE-2017-10681

Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to…

Fix: after 2.9.1
Fix from $1,950 2017-06-29
Jasperreports Server HIGH 8.8
CVE-2017-5528

Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-sit…

Fix: after 6.3.0
Fix from $1,950 2017-06-29
Vimbadmin HIGH 8.8
CVE-2017-6086

Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.15 allow remote attackers to h…

No fix yet
Fix from $1,950 2017-06-27
Kibana Reporting HIGH 8.8
CVE-2016-1000218

Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an …

Mitigation only
Fix from $1,950 2017-06-16
Simplece HIGH 8.8
CVE-2017-9673

In SimpleCE 2.3.0, a CSRF vulnerability can be exploited to add an administrator account (via the index.php/user/new URI) or change its settings (via…

Fix: after 2.3.0
Fix from $1,950 2017-06-15
Prime Collaboration Assurance HIGH 8.8
CVE-2017-6659

A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to condu…

Mitigation only
Fix from $1,950 2017-06-13
Garoon HIGH 8.8
CVE-2016-4907

Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.

Mitigation only
Fix from $1,950 2017-06-09
Cg Wlr300nx Firmware HIGH 8.8
CVE-2016-7809

Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows remote attackers to hijack the authentica…

Fix: after 1.20
Fix from $1,950 2017-06-09
Wnc01wh Firmware HIGH 8.8
CVE-2016-7822

Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackers to hijac…

Fix: after 1.0.0.8
Fix from $1,950 2017-06-09
Zend Framework HIGH 8.8
CVE-2015-1786

Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.

Mitigation only
Fix from $1,950 2017-06-08