Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unified Communications Manager MEDIUM 6.5
CVE-2017-3877

A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct…

Mitigation only
Fix from $1,600 2017-03-17
Drupal HIGH 7.5
CVE-2017-6379

Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a …

Mitigation only
Fix from $1,950 2017-03-16
Bigtree Cms HIGH 7.1
CVE-2017-6914

CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page. A user can be deleted.

Patch available
Fix from $1,950 2017-03-15
Dgn2200 Firmware HIGH 8.8
CVE-2017-6366

Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijac…

Fix: after 10.0.0.50
Fix from $1,950 2017-03-15
Zammad CRITICAL 9.8
CVE-2017-6080

An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP A…

Fix: after 1.0.3
Fix from $2,300 2017-03-13
Zammad HIGH 8.8
CVE-2017-6081

A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cr…

Fix: after 1.0.3
Fix from $1,950 2017-03-13
Kk002 Ip Camera Firmware HIGH 8.8
CVE-2017-6180

Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entir…

No fix yet
Fix from $1,950 2017-03-13
WordPress MEDIUM 6.5
CVE-2017-6819

In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive…

Fix: after 4.7.2
Fix from $1,600 2017-03-12
Di 524 Firmware HIGH 8.0
CVE-2017-5633

Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) chan…

No fix yet
Fix from $1,950 2017-03-06
Dsl 2730u Firmware HIGH 8.8
CVE-2017-6411

Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any p…

No fix yet
Fix from $1,950 2017-03-06
Umbraco HIGH 8.8
CVE-2015-8814

Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demons…

Patch available
Fix from $1,950 2017-03-03
Zoneminder HIGH 8.8
CVE-2016-10206

Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requ…

Fix: after 1.30.0
Fix from $1,950 2017-03-03
Ruggedcom Network Management Software HIGH 8.8
CVE-2017-2682

The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery …

Fix: after 2.0.2
Fix from $1,950 2017-02-27
Dashboard Application Services Hub HIGH 8.8
CVE-2016-9975

IBM Jazz for Service Management 1.1.2.1 and 1.1.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Patch available
Fix from $1,950 2017-02-24
Dg Hr1400 Firmware HIGH 8.8
CVE-2017-6127

Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.02 allow …

No fix yet
Fix from $1,950 2017-02-21
Genixcms CRITICAL 9.8
CVE-2017-5959

CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.

Fix: after 1.0.1
Fix from $2,300 2017-02-21
Carbon MEDIUM 5.7
CVE-2016-4315

Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for req…

Patch available
Fix from $1,600 2017-02-17
Identity Server HIGH 8.8
CVE-2016-4311

Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authent…

Patch available
Fix from $1,950 2017-02-17
Tivoli Storage Manager For Virtual Environments Data Protection For Vmware HIGH 8.8
CVE-2016-6033

IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute…

Patch available
Fix from $1,950 2017-02-15
Smart Security Manager HIGH 7.5
CVE-2017-5169

An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior. Multiple Cross Site Request Forgery vulnerabilities have bee…

Fix: after 1.5
Fix from $1,950 2017-02-13
Nport 5100 Series Firmware HIGH 8.8
CVE-2016-9365

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2…

Fix: after 3.10
Fix from $1,950 2017-02-13
Vmu C Em Firmware CRITICAL 10.0
CVE-2017-5145

An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitat…

Mitigation only
Fix from $2,300 2017-02-13
Universal Multifunctional Electric Power Quality Meter Firmware HIGH 7.6
CVE-2017-5165

An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. There is no CSRF Token generated per page and/or per (sensi…

Mitigation only
Fix from $1,950 2017-02-13
Jenesys Bas Bridge HIGH 8.8
CVE-2016-8369

An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application does not sufficiently verify if a request was inte…

Fix: after 1.1.8
Fix from $1,950 2017-02-13
Ion5000 HIGH 8.8
CVE-2016-5809

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 ser…

No fix yet
Fix from $1,950 2017-02-13
Iologik E1200 Series Firmware MEDIUM 6.3
CVE-2016-8350

An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmwa…

Fix: after 3.13
Fix from $1,600 2017-02-13
Snap Creator Framework MEDIUM 6.3
CVE-2016-5372

Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication …

Fix: after 4.3.0
Fix from $1,600 2017-02-07
Atutor HIGH 8.8
CVE-2016-2539

Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of…

Fix: after 2.2.1
Fix from $1,950 2017-02-07
Zoneminder HIGH 8.8
CVE-2017-5368

ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote atta…

No fix yet
Fix from $1,950 2017-02-06
Security Key Lifecycle Manager HIGH 8.8
CVE-2016-6103

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2017-02-02