Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Sterling Selling And Fulfillment Foundation HIGH 8.0
CVE-2016-9991

IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau…

Patch available
Fix from $1,950 2017-06-08
Atmail HIGH 8.8
CVE-2017-9517

atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.

Fix: after 7.8.0.1
Fix from $1,950 2017-06-08
Atmail HIGH 8.8
CVE-2017-9518

atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.

Fix: after 7.8.0.1
Fix from $1,950 2017-06-08
Atmail HIGH 8.8
CVE-2017-9519

atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.

Fix: after 7.8.0.1
Fix from $1,950 2017-06-08
Bigtree Cms HIGH 8.8
CVE-2017-9444

BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/…

Fix: after 4.2.18
Fix from $1,950 2017-06-05
B305hw2 Firmware HIGH 8.8
CVE-2017-8836

CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-bui…

No fix yet
Fix from $1,950 2017-06-05
Lenovo Service Bridge HIGH 8.8
CVE-2016-8229

A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server…

Mitigation only
Fix from $1,950 2017-06-04
Bigtree Cms HIGH 8.8
CVE-2017-9379

Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and th…

Fix: after 4.2.18
Fix from $1,950 2017-06-02
Bigtree Cms HIGH 8.8
CVE-2017-9365

CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false…

Fix: after 4.2.18
Fix from $1,950 2017-06-02
Oncell G3110 Hspa Firmware HIGH 8.8
CVE-2017-7917

A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Vers…

Fix: after 1.4
Fix from $1,950 2017-05-29
Serverprotect HIGH 8.8
CVE-2017-9033

Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authe…

Patch available
Fix from $1,950 2017-05-26
Cf Release HIGH 8.8
CVE-2015-3191

With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or e…

Fix: after 209
Fix from $1,950 2017-05-25
Archiva HIGH 8.0
CVE-2017-5657

Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the …

Fix: after 2.2.1
Fix from $1,950 2017-05-22
L 04d Firmware HIGH 8.8
CVE-2016-4854

Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijack the authentication of admin…

Mitigation only
Fix from $1,950 2017-05-22
Olivecart HIGH 8.8
CVE-2016-4904

Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote att…

Fix: after 3.1.7
Fix from $1,950 2017-05-22
Industrial Ethernet 1000 Series Firmware HIGH 8.8
CVE-2017-6634

A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,950 2017-05-22
Mantisbt MEDIUM 6.5
CVE-2017-7620

MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpret…

Fix: after 1.3.10
Fix from $1,600 2017-05-21
WordPress HIGH 8.6
CVE-2017-9062

In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.

Fix: after 4.7.4
Fix from $1,950 2017-05-18
WordPress HIGH 8.8
CVE-2017-9064

In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not requi…

Fix: after 4.7.4
Fix from $1,950 2017-05-18
Zimbra Collaboration Suite HIGH 8.8
CVE-2016-3403

Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers t…

Fix: after 8.6.0
Fix from $1,950 2017-05-17
Cxf Fediz HIGH 8.8
CVE-2017-7661

Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty…

Fix: after 1.4.0
Fix from $1,950 2017-05-16
Cxf Fediz HIGH 8.8
CVE-2017-7662

Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows c…

Fix: after 1.3.2
Fix from $1,950 2017-05-16
Mailcow\ HIGH 8.8
CVE-2017-8928

mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.

Patch available
Fix from $1,950 2017-05-14
Simple Invoices HIGH 8.8
CVE-2017-8930

Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of ad…

Mitigation only
Fix from $1,950 2017-05-14
Basercms HIGH 8.8
CVE-2016-4876

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of admini…

Patch available
Fix from $1,950 2017-05-12
Basercms HIGH 8.8
CVE-2016-4878

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of admini…

Patch available
Fix from $1,950 2017-05-12
Basercms HIGH 8.8
CVE-2016-4879

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authenticati…

Fix: after 3.0.10
Fix from $1,950 2017-05-12
Basercms HIGH 8.8
CVE-2016-4881

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authenticati…

Patch available
Fix from $1,950 2017-05-12
Basercms HIGH 8.8
CVE-2016-4882

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of admini…

Patch available
Fix from $1,950 2017-05-12
Basercms HIGH 8.8
CVE-2016-4884

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authenticati…

Patch available
Fix from $1,950 2017-05-12