Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Setucocms HIGH 8.8
CVE-2016-4891

Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator t…

Mitigation only
Fix from $1,950 2017-04-12
Awk 3131a Firmware HIGH 8.8
CVE-2016-8718

An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running f…

No fix yet
Fix from $1,950 2017-04-12
Jira HIGH 8.8
CVE-2016-4319

Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.

Fix: after 7.1.8
Fix from $1,950 2017-04-10
Axis Communications Firmware HIGH 8.8
CVE-2015-8255

AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.

No fix yet
Fix from $1,950 2017-04-10
Faveo Helpdesk HIGH 8.0
CVE-2017-7571

public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.

No fix yet
Fix from $1,950 2017-04-06
Helpdezk HIGH 8.8
CVE-2017-7446

HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.

Patch available
Fix from $1,950 2017-04-05
Helpdezk HIGH 8.8
CVE-2017-7447

HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.

Patch available
Fix from $1,950 2017-04-05
Disposal And Governance Management For It HIGH 8.8
CVE-2016-6100

IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is …

Mitigation only
Fix from $1,950 2017-04-05
Dir 615 Firmware HIGH 8.8
CVE-2017-7398

D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted acti…

No fix yet
Fix from $1,950 2017-04-04
Al3g Firmware HIGH 8.8
CVE-2016-10313

Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.0…

No fix yet
Fix from $1,950 2017-04-03
Fusionmanager HIGH 8.8
CVE-2014-9136

Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the u…

Mitigation only
Fix from $1,950 2017-04-02
Fusionmanager HIGH 8.8
CVE-2014-9137

Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG22…

Mitigation only
Fix from $1,950 2017-04-02
Tecal Rh1288 V2 Firmware HIGH 8.8
CVE-2014-9694

Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, T…

Mitigation only
Fix from $1,950 2017-04-02
Sterling Selling And Fulfillment Foundation HIGH 8.8
CVE-2016-8917

IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Patch available
Fix from $1,950 2017-03-31
Ruggedcom Rox I HIGH 8.8
CVE-2017-2688

The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privil…

Fix: after 2.9.0
Fix from $1,950 2017-03-29
Revive Adserver HIGH 8.8
CVE-2016-9127

Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF atta…

Fix: after 3.2.2
Fix from $1,950 2017-03-28
Revive Adserver HIGH 8.8
CVE-2016-9455

Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable t…

Fix: after 3.2.2
Fix from $1,950 2017-03-28
Revive Adserver HIGH 8.8
CVE-2016-9456

Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interfa…

Fix: after 3.2.2
Fix from $1,950 2017-03-28
Subrion Cms HIGH 8.8
CVE-2017-6002

Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body par…

Mitigation only
Fix from $1,950 2017-03-27
Subrion Cms HIGH 8.8
CVE-2017-6066

Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title…

Mitigation only
Fix from $1,950 2017-03-27
Subrion Cms HIGH 8.8
CVE-2017-6068

Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.

Mitigation only
Fix from $1,950 2017-03-27
Subrion Cms HIGH 8.8
CVE-2017-6069

Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.

Mitigation only
Fix from $1,950 2017-03-27
Mediawiki HIGH 8.8
CVE-2015-8623

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in cons…

Fix: after 1.23.11
Fix from $1,950 2017-03-23
Mediawiki HIGH 8.8
CVE-2015-8624

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.2…

Fix: after 1.23.11
Fix from $1,950 2017-03-23
Access Manager HIGH 8.8
CVE-2016-5758

A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by re…

Mitigation only
Fix from $1,950 2017-03-23
Dir 600m Firmware HIGH 8.8
CVE-2017-5874

CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or…

Fix: after 1.0.1
Fix from $1,950 2017-03-22
Weblog HIGH 8.8
CVE-2016-4504

A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlim…

Mitigation only
Fix from $1,950 2017-03-21
Junos Space HIGH 8.8
CVE-2016-4928

Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Spac…

Fix: after 15.2
Fix from $1,950 2017-03-20
Ftp Voyager HIGH 8.8
CVE-2017-6803

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 a…

No fix yet
Fix from $1,950 2017-03-20
Debian Linux HIGH 8.8
CVE-2017-7178

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitr…

Fix: 1.3.14+
Fix from $1,950 2017-03-18