Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Basercms HIGH 8.8
CVE-2016-4885

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attackers to hijack the authenticati…

Patch available
Fix from $1,950 2017-05-12
Basercms HIGH 8.8
CVE-2016-4886

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authenticati…

Patch available
Fix from $1,950 2017-05-12
Basercms HIGH 8.8
CVE-2016-4887

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the authenti…

Patch available
Fix from $1,950 2017-05-12
Content Analysis HIGH 8.8
CVE-2016-9092

The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site r…

Mitigation only
Fix from $1,950 2017-05-11
Interact HIGH 8.8
CVE-2016-5889

IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized …

Patch available
Fix from $1,950 2017-05-10
Rt Ac1750 Firmware HIGH 8.8
CVE-2017-5891

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 have Login Page CSRF and Save Settings CSRF.

Patch available
Fix from $1,950 2017-05-10
Mautic HIGH 8.8
CVE-2017-8874

Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests …

Mitigation only
Fix from $1,950 2017-05-10
Clean Login MEDIUM 6.5
CVE-2017-8875

CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.

Patch available
Fix from $1,600 2017-05-10
Allen Disk MEDIUM 6.5
CVE-2017-8848

Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.

Patch available
Fix from $1,600 2017-05-08
Imanager HIGH 8.8
CVE-2017-7431

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.

Mitigation only
Fix from $1,950 2017-05-03
Websphere Application Server HIGH 8.8
CVE-2017-1194

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou…

Patch available
Fix from $1,950 2017-04-28
Knowledge HIGH 8.8
CVE-2017-2097

Cross-site request forgery (CSRF) vulnerability in Knowledge versions prior to v1.7.0 allows remote attackers to hijack the authentication of adminis…

Fix: after 1.4.1
Fix from $1,950 2017-04-28
Appgoat HIGH 8.8
CVE-2017-2102

Cross-site request forgery (CSRF) vulnerability in Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remot…

Fix: after 3.0.0
Fix from $1,950 2017-04-28
Kallithea HIGH 8.8
CVE-2016-3691

Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method.

Fix: after 0.3.1
Fix from $1,950 2017-04-24
E107 MEDIUM 6.5
CVE-2017-8098

e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forge…

Patch available
Fix from $1,600 2017-04-24
Whizz HIGH 8.1
CVE-2017-8099

There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a G…

Fix: after 1.1
Fix from $1,950 2017-04-24
Copysafe Web Protection MEDIUM 6.5
CVE-2017-8100

There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings.

Fix: after 2.5
Fix from $1,600 2017-04-24
Serendipity HIGH 8.8
CVE-2017-8101

There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.

Patch available
Fix from $1,950 2017-04-24
Dcs 2230l Firmware HIGH 8.8
CVE-2017-7852

D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's s…

Fix: after 2.13.15
Fix from $1,950 2017-04-24
Concrete Cms MEDIUM 6.5
CVE-2017-8082

concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking…

No fix yet
Fix from $1,600 2017-04-24
Fedora HIGH 8.8
CVE-2016-0720

Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.

Fix: after 0.9.148
Fix from $1,950 2017-04-21
Wondercms HIGH 8.8
CVE-2017-7951

WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.

Fix: after 2.0.2
Fix from $1,950 2017-04-21
Openmrs Module Reporting HIGH 8.8
CVE-2017-7990

The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScri…

Patch available
Fix from $1,950 2017-04-21
Password Manager Pro HIGH 8.0
CVE-2016-1161

Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).

Fix: after 8.5
Fix from $1,950 2017-04-20
Moodle HIGH 8.8
CVE-2016-3734

Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.…

Patch available
Fix from $1,950 2017-04-20
Jboss Bpm Suite HIGH 8.8
CVE-2016-5401

Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for re…

Mitigation only
Fix from $1,950 2017-04-20
Wonderware Intouch Access Anywhere HIGH 8.8
CVE-2017-5156

A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client requ…

Fix: after 11.5.2
Fix from $1,950 2017-04-20
Bigtree Cms HIGH 8.8
CVE-2017-7881

BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the require…

Fix: after 4.2.17
Fix from $1,950 2017-04-15
Flatcore Cms HIGH 8.8
CVE-2017-7877

CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.

Patch available
Fix from $1,950 2017-04-14
Teampass HIGH 8.8
CVE-2015-7563

Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticat…

Fix: after 2.1.24.0
Fix from $1,950 2017-04-12