Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Spectrum Control HIGH 8.8
CVE-2016-8941

IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Patch available
Fix from $1,950 2017-02-01
Kenexa Lcms Premier HIGH 8.8
CVE-2016-5937

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized acti…

Patch available
Fix from $1,950 2017-02-01
Tivoli Storage Manager HIGH 8.8
CVE-2016-6045

IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2017-02-01
Security Access Manager 9.0 Firmware HIGH 8.8
CVE-2016-3029

IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized a…

Patch available
Fix from $1,950 2017-02-01
Hybrid Meeting Server HIGH 8.8
CVE-2016-9218

A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack …

Mitigation only
Fix from $1,950 2017-01-26
Webex Meetings Server HIGH 8.8
CVE-2017-3794

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack …

Mitigation only
Fix from $1,950 2017-01-26
Grails HIGH 8.8
CVE-2016-6521

Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows…

Fix: after 1.5.9
Fix from $1,950 2017-01-23
Zimbra Collaboration Suite HIGH 8.8
CVE-2016-3406

Multiple cross-site request forgery (CSRF) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to hijack the authentication o…

Fix: after 8.6.0
Fix from $1,950 2017-01-18
WordPress MEDIUM 6.5
CVE-2016-6897EPSS 28%

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 a…

Fix: after 4.5.5
Fix from $1,600 2017-01-18
Spip HIGH 8.8
CVE-2016-7980

Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authen…

Fix: after 3.1.2
Fix from $1,950 2017-01-18
Cms Made Simple HIGH 8.0
CVE-2016-7904

Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrator…

Fix: after 2.1.5
Fix from $1,950 2017-01-16
WordPress HIGH 8.8
CVE-2017-5492

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to…

Fix: after 4.7
Fix from $1,950 2017-01-15
WordPress HIGH 8.8
CVE-2017-5489

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims…

Fix: after 4.7
Fix from $1,950 2017-01-15
Virtual Traffic Manager HIGH 8.0
CVE-2016-8201

A CSRF vulnerability in Brocade Virtual Traffic Manager versions released prior to and including 11.0 could allow an attacker to trick a logged-in us…

Fix: after 11.0
Fix from $1,950 2017-01-14
Ntopng HIGH 8.8
CVE-2017-5473

Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as dem…

Fix: after 2.4
Fix from $1,950 2017-01-14
Serendipity HIGH 8.8
CVE-2017-5475

comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.

Fix: after 2.0.5
Fix from $1,950 2017-01-14
Serendipity HIGH 8.8
CVE-2017-5476

Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.

Fix: after 2.0.5
Fix from $1,950 2017-01-14
Web2py HIGH 8.8
CVE-2016-4808

Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user …

Fix: after 2.14.5
Fix from $1,950 2017-01-11
Population Health HIGH 8.8
CVE-2015-4593

eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote a…

No fix yet
Fix from $1,950 2017-01-10
Xfinity Gateway Router Dpc3941t Firmware HIGH 8.0
CVE-2016-7454

CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an at…

No fix yet
Fix from $1,950 2016-12-17
Experience Manager HIGH 8.8
CVE-2016-7885

Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks.

Fix: after 6.2.0
Fix from $1,950 2016-12-15
D6220 Firmware HIGH 8.8
CVE-2016-6277 KEVEPSS 100%

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.…

Fix: after 1.0.7.2_1.1.93
Fix from $1,950 2016-12-14
Emergency Responder HIGH 8.8
CVE-2016-6468

A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross…

Mitigation only
Fix from $1,950 2016-12-14
phpMyAdmin CRITICAL 9.8
CVE-2016-9866

An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from th…

Patch available
Fix from $2,300 2016-12-11
Forms Experience Builder HIGH 8.0
CVE-2016-2884

Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configu…

Patch available
Fix from $1,950 2016-11-30
Qradar Security Information And Event Manager HIGH 8.0
CVE-2016-2878

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to …

Mitigation only
Fix from $1,950 2016-11-30
Bigfix Remote Control HIGH 8.8
CVE-2016-2963

Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arb…

Fix: after 9.1.2
Fix from $1,950 2016-11-30
Simatic S7 300 Cpu Firmware HIGH 8.8
CVE-2016-8673

A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl…

Mitigation only
Fix from $1,950 2016-11-23
Hosted Collaboration Mediation Fulfillment MEDIUM 6.5
CVE-2016-6454

A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfillment application could allo…

Mitigation only
Fix from $1,600 2016-11-03
Meeting Server HIGH 8.8
CVE-2016-6444

A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against…

Mitigation only
Fix from $1,950 2016-10-27