Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Jazz Reporting Service HIGH 8.8
CVE-2015-7465

Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifi…

Mitigation only
Fix from $1,950 2016-01-10
Storeonce Backup System Software HIGH 8.8
CVE-2015-5445

Cross-site request forgery (CSRF) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to hijack the …

Fix: after 3.13.0
Fix from $1,950 2016-01-05
Connections MEDIUM 5.4
CVE-2015-5037

Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows …

Fix: after 3.0.1.1
Fix from $1,600 2016-01-03
Mashups Center HIGH 8.8
CVE-2015-7407

Cross-site request forgery (CSRF) vulnerability in Lotus Mashups in IBM Mashup Center 3.0.0.1 allows remote attackers to hijack the authentication of…

Mitigation only
Fix from $1,950 2016-01-02
Gs1900 10hp Firmware HIGH 8.8
CVE-2015-5990

Cross-site request forgery (CSRF) vulnerability on Belkin F9K1102 2 devices with firmware 2.10.17 allows remote attackers to hijack the authenticatio…

Fix: 2.50+
Fix from $1,950 2015-12-31
Nbg 418n Firmware HIGH 8.0
CVE-2015-7284

Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authenti…

Mitigation only
Fix from $1,950 2015-12-31
Wrt300n Dd Firmware HIGH 8.8
CVE-2015-7281

Cross-site request forgery (CSRF) vulnerability on ReadyNet WRT300N-DD devices with firmware 1.0.26 allows remote attackers to hijack the authenticat…

Mitigation only
Fix from $1,950 2015-12-31
R10000 Firmware HIGH 8.8
CVE-2015-7278

Cross-site request forgery (CSRF) vulnerability on Amped Wireless R10000 devices with firmware 2.5.2.11 allows remote attackers to hijack the authent…

Mitigation only
Fix from $1,950 2015-12-31
Medialink Mwn Wapr300n Firmware HIGH 8.8
CVE-2015-5996

Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allows remote attackers to hijack…

Fix: after 5.07.50
Fix from $1,950 2015-12-31
Orientdb HIGH 8.8
CVE-2015-2912

The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callb…

Fix: after 2.0.14
Fix from $1,950 2015-12-31
Ewon Firmware HIGH 8.0
CVE-2015-7925

Cross-site request forgery (CSRF) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to hijack the authentication of …

Fix: after 10.0s0
Fix from $1,950 2015-12-23
Moscad Ip Gateway Firmware HIGH 7.5
CVE-2015-7936

Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of admin…

Mitigation only
Fix from $1,950 2015-12-23
Joomla\! MEDIUM 6.8
CVE-2015-8563

Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote at…

Mitigation only
Fix from $1,600 2015-12-16
Dpq3925 8x4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter MEDIUM 6.8
CVE-2015-6378

Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbi…

Mitigation only
Fix from $1,600 2015-12-14
Emergency Responder MEDIUM 6.8
CVE-2015-6405

Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attackers to hijack the authenticatio…

Mitigation only
Fix from $1,600 2015-12-13
Unity Connection MEDIUM 6.8
CVE-2015-6408

Cross-site request forgery (CSRF) vulnerability in Cisco Unity Connection 11.5(0.98) allows remote attackers to hijack the authentication of arbitrar…

Mitigation only
Fix from $1,600 2015-12-12
Kibana MEDIUM 6.8
CVE-2015-8131

Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the aut…

Fix: after 4.1.2
Fix from $1,600 2015-12-07
Jenkins MEDIUM 6.8
CVE-2015-5318

Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which makes it easier for remote atta…

Fix: after 3.1
Fix from $1,600 2015-11-25
Operations Orchestration MEDIUM 6.8
CVE-2015-5451

Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the au…

Fix: after 10.22.0
Fix from $1,600 2015-11-23
Na Model 862 Gw Mono Firmware MEDIUM 6.8
CVE-2015-7291

Cross-site request forgery (CSRF) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmw…

Mitigation only
Fix from $1,600 2015-11-21
Telepresence Video Communication Server Software MEDIUM 6.8
CVE-2015-6376

Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to hijack the a…

Mitigation only
Fix from $1,600 2015-11-21
Debian Linux MEDIUM 6.8
CVE-2015-7984

Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition …

Fix: 5.2.8 / 5.2.11+
Fix from $1,600 2015-11-19
Dir 816l Firmware MEDIUM 6.8
CVE-2015-5999

Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote att…

Fix: after 2.05.b02
Fix from $1,600 2015-11-18
Firepower Extensible Operating System MEDIUM 6.8
CVE-2015-6373

Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote att…

Mitigation only
Fix from $1,600 2015-11-18
Prime Collaboration Assurance MEDIUM 6.8
CVE-2015-6330

Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote attackers to hijack the authent…

Mitigation only
Fix from $1,600 2015-11-18
WordPress MEDIUM 6.8
CVE-2015-5731

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication o…

Fix: after 4.2.3
Fix from $1,600 2015-11-09
Security Qradar Incident Forensics MEDIUM 6.8
CVE-2015-1997

Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar Vulnerability Manager 7.2.x before 7.2.5 Patch 5 allows remote attackers to hi…

Mitigation only
Fix from $1,600 2015-11-08
Oxwall MEDIUM 6.8
CVE-2015-5534

Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the authentication of administrators…

Fix: after 1.7.4
Fix from $1,600 2015-11-02
Mango Automation MEDIUM 6.8
CVE-2015-6493

Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authent…

Patch available
Fix from $1,600 2015-10-28
Umg 508 MEDIUM 6.8
CVE-2015-3967

Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attackers to hijack the authenticati…

Patch available
Fix from $1,600 2015-10-28