Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Service Manager HIGH 8.0
CVE-2016-4371

HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, mo…

Mitigation only
Fix from $1,950 2016-06-19
Bac 5051e Firmware HIGH 8.8
CVE-2016-4494

Cross-site request forgery (CSRF) vulnerability on KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allows remote attackers to hijack the…

Mitigation only
Fix from $1,950 2016-06-10
Intuitive 650 Tdb Controller HIGH 8.0
CVE-2016-4506

Cross-site request forgery (CSRF) vulnerability on Resource Data Management (RDM) Intuitive 650 TDB Controller devices before 2.1.24 allows remote au…

Fix: after 2.1
Fix from $1,950 2016-05-31
Miineport E2 1242 Firmware HIGH 8.8
CVE-2016-2285

Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with…

Mitigation only
Fix from $1,950 2016-05-31
Moodle HIGH 8.8
CVE-2016-2157

Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.…

Fix: after 2.6.11
Fix from $1,950 2016-05-22
Ec Cube HIGH 8.8
CVE-2016-1201

Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack the authentication of adminis…

Patch available
Fix from $1,950 2016-04-30
Vipr Srm HIGH 8.8
CVE-2016-0891

Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remote attackers to hijack the au…

Fix: after 3.6.4
Fix from $1,950 2016-04-20
Zimbra Collaboration Server HIGH 8.8
CVE-2015-6541

Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attacke…

Fix: after 8.0.9
Fix from $1,950 2016-04-08
Casebook Plugin HIGH 8.8
CVE-2016-1174

Cross-site request forgery (CSRF) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication…

Fix: after 0.9.2
Fix from $1,950 2016-04-06
Casebook Plugin HIGH 8.8
CVE-2016-1172

Cross-site request forgery (CSRF) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication …

Fix: after 0.9.2
Fix from $1,950 2016-04-06
Casebook Plugin HIGH 8.8
CVE-2016-1170

Cross-site request forgery (CSRF) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to hijack the authentication…

Fix: after 0.9.3
Fix from $1,950 2016-04-06
Wf800hp Firmware HIGH 8.8
CVE-2016-1168

Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows remote attackers to hijack the a…

Fix: after 1.0.17
Fix from $1,950 2016-04-01
Wg300hp Firmware HIGH 8.8
CVE-2016-1167

Cross-site request forgery (CSRF) vulnerability on NEC Aterm WG300HP devices allows remote attackers to hijack the authentication of arbitrary users.

Fix: after 1.0.8
Fix from $1,950 2016-04-01
Endpoint Protection Manager HIGH 8.0
CVE-2015-8152

Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users …

Fix: after 12.1
Fix from $1,950 2016-03-18
Flashsystem V9000 Firmware HIGH 8.8
CVE-2015-7446

Cross-site request forgery (CSRF) vulnerability in IBM Flash System V9000 7.4 before 7.4.1.4, 7.5 before 7.5.1.3, and 7.6 before 7.6.0.4 allows remot…

Mitigation only
Fix from $1,950 2016-03-12
Cg Wlbargmh Firmware HIGH 8.8
CVE-2016-1158

Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authentication of…

Mitigation only
Fix from $1,950 2016-03-03
Tomcat HIGH 8.8
CVE-2015-5351EPSS 10%

The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions a…

No fix yet
Fix from $1,950 2016-02-25
Moodle HIGH 8.8
CVE-2015-5338

Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, an…

Fix: after 2.6.11
Fix from $1,950 2016-02-22
Office HIGH 8.8
CVE-2016-1151

Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication …

Mitigation only
Fix from $1,950 2016-02-17
Emptoris Contract Management HIGH 8.8
CVE-2015-5050

Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.…

Mitigation only
Fix from $1,950 2016-02-15
Smartgrid Lighthouse Sensor Management System HIGH 8.8
CVE-2016-0863

Cross-site request forgery (CSRF) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 B…

Fix: after 5.0
Fix from $1,950 2016-02-13
Connect HIGH 8.8
CVE-2016-0948

Cross-site request forgery (CSRF) vulnerability in Adobe Connect before 9.5.2 allows remote attackers to hijack the authentication of unspecified vic…

Fix: after 9.5
Fix from $1,950 2016-02-10
Moveit Mobile HIGH 8.8
CVE-2015-7678

Multiple cross-site request forgery (CSRF) vulnerabilities in Ipswitch MOVEit Mobile 1.2.0.962 and earlier allow remote attackers to hijack the authe…

Fix: after 1.2.0.962
Fix from $1,950 2016-02-10
Openshift HIGH 8.8
CVE-2015-7537

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication o…

Fix: after 3.1
Fix from $1,950 2016-02-03
Vulnerability Manager HIGH 8.8
CVE-2016-2199

Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations and Remediation management page in Enterprise Manager in McAfee Vulne…

Fix: after 7.5.9
Fix from $1,950 2016-02-01
Home Spot Cube Firmware HIGH 7.5
CVE-2016-1139

Cross-site request forgery (CSRF) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to hijack the authentication of unspe…

Mitigation only
Fix from $1,950 2016-01-30
Cakephp HIGH 8.8
CVE-2015-8379

CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.

Patch available
Fix from $1,950 2016-01-26
Whr 1166dhp Firmware HIGH 8.8
CVE-2016-1134

Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and e…

Fix: after 1.90
Fix from $1,950 2016-01-22
Websphere Commerce HIGH 8.8
CVE-2015-5007

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows re…

Mitigation only
Fix from $1,950 2016-01-15
Webaccess HIGH 8.8
CVE-2015-3946

Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote attackers to hijack the authentication of unspecified…

Fix: after 8.0
Fix from $1,950 2016-01-15