Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Finesse HIGH 8.8
CVE-2016-6442

A vulnerability in Cisco Finesse Agent and Supervisor Desktop Software could allow an unauthenticated, remote attacker to conduct a cross-site reques…

Mitigation only
Fix from $1,950 2016-10-27
Wireless H500 HIGH 8.8
CVE-2016-1000213

Ruckus Wireless H500 web management interface CSRF

Mitigation only
Fix from $1,950 2016-10-25
Unified Contact Center Express HIGH 8.8
CVE-2016-6427

Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center E…

Mitigation only
Fix from $1,950 2016-10-06
Firesight System Software HIGH 8.8
CVE-2016-6417

Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote…

Mitigation only
Fix from $1,950 2016-10-05
Cloud Foundry Uaa Bosh CRITICAL 9.6
CVE-2016-6637

Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and…

Fix: after 241
Fix from $2,300 2016-09-30
Connections HIGH 8.8
CVE-2016-3007

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticate…

Patch available
Fix from $1,950 2016-09-26
Hvl A2.0 Firmware HIGH 8.8
CVE-2016-4845

Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2…

Mitigation only
Fix from $1,950 2016-09-24
Jackrabbit HIGH 8.8
CVE-2016-6801

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x be…

Mitigation only
Fix from $1,950 2016-09-21
Ws331a Router Firmware MEDIUM 6.1
CVE-2016-6158

Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allow remote attac…

Mitigation only
Fix from $1,600 2016-09-21
Vipr Srm MEDIUM 6.1
CVE-2016-6642

Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authentication of administrators f…

Fix: after 3.7.1
Fix from $1,600 2016-09-18
Jboss Bpm Suite HIGH 8.8
CVE-2016-7034

The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query s…

Mitigation only
Fix from $1,950 2016-09-07
Mailman HIGH 8.8
CVE-2016-7123

Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authent…

Fix: after 2.1.14
Fix from $1,950 2016-09-02
Mailman HIGH 8.8
CVE-2016-6893

Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the aut…

Mitigation only
Fix from $1,950 2016-09-02
Small Business 220 Series Smart Plus Switches HIGH 8.8
CVE-2016-1470

Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.…

No fix yet
Fix from $1,950 2016-09-02
Leap HIGH 8.8
CVE-2016-4069

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for r…

Fix: after 1.1.4
Fix from $1,950 2016-08-25
WordPress HIGH 8.8
CVE-2016-6635

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before…

Fix: after 4.4.2
Fix from $1,950 2016-08-07
Dm Txrx 100 Str Firmware HIGH 8.8
CVE-2016-5671

Multiple cross-site request forgery (CSRF) vulnerabilities on Crestron Electronics DM-TXRX-100-STR devices with firmware through 1.3039.00040 allow r…

Fix: after 1.2866.00026
Fix from $1,950 2016-08-03
Filr HIGH 7.2
CVE-2016-1607

Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote a…

Fix: after 2.0
Fix from $1,950 2016-08-01
Archiva HIGH 8.8
CVE-2016-4469EPSS 8%

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of…

Fix: after 1.3.9
Fix from $1,950 2016-07-28
Webex Meetings Server HIGH 8.8
CVE-2016-1448

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary …

Mitigation only
Fix from $1,950 2016-07-17
Fortiweb HIGH 8.8
CVE-2016-4066

Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb before 5.5.3 allows remote attackers to hijack the authentication of administrat…

Fix: after 5.5.2
Fix from $1,950 2016-07-13
Jazz Reporting Service HIGH 8.8
CVE-2016-2889

Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x bef…

Mitigation only
Fix from $1,950 2016-07-08
Struts HIGH 8.8
CVE-2016-4430

Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attac…

Mitigation only
Fix from $1,950 2016-07-04
Websphere Commerce HIGH 8.0
CVE-2016-2863

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.2 all…

Mitigation only
Fix from $1,950 2016-07-03
Pr 400mi Firmware HIGH 8.8
CVE-2016-1228

Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlie…

Fix: after 07.00.1006
Fix from $1,950 2016-07-03
Vrealize Log Insight HIGH 8.8
CVE-2016-2082

Cross-site request forgery (CSRF) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to hijack the authent…

Patch available
Fix from $1,950 2016-07-03
Tririga Application Platform HIGH 8.0
CVE-2016-0386

Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 al…

Mitigation only
Fix from $1,950 2016-07-02
Endpoint Protection Manager HIGH 8.0
CVE-2016-3653

Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 a…

Fix: after 12.1.6
Fix from $1,950 2016-06-30
Websphere Portal HIGH 8.8
CVE-2016-2901

Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Man…

Mitigation only
Fix from $1,950 2016-06-26
Etx R Firmware HIGH 8.8
CVE-2016-4820

Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the authentication of arbitrary us…

Mitigation only
Fix from $1,950 2016-06-19