Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2015-5188

Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly …

Fix: after 6.4.3
Fix from $1,600 2015-10-27
Ec Cube MEDIUM 5.1
CVE-2015-5665

Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbit…

Mitigation only
Fix from $1,600 2015-10-27
Extplorer MEDIUM 6.8
CVE-2015-5660

Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for…

Fix: after 2.1.7
Fix from $1,600 2015-10-16
Revive Adserver MEDIUM 6.8
CVE-2015-7366

Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.2.2 allow remote attackers to hijack the authentication of use…

Fix: after 3.2.1
Fix from $1,600 2015-10-14
Revive Adserver MEDIUM 6.8
CVE-2015-7364

The HTML_Quickform library, as used in Revive Adserver before 3.2.2, allows remote attackers to bypass the CSRF protection mechanism via an empty tok…

Fix: after 3.2.1
Fix from $1,600 2015-10-14
Websphere Extreme Scale MEDIUM 6.0
CVE-2015-2026

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authentica…

Patch available
Fix from $1,600 2015-10-04
Openpages Grc Platform MEDIUM 6.8
CVE-2015-0145

Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 befor…

Patch available
Fix from $1,600 2015-10-03
Vulnerability Manager MEDIUM 6.8
CVE-2015-7612

Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations page in Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.…

Fix: after 7.5.9
Fix from $1,600 2015-10-01
X2crm MEDIUM 6.8
CVE-2015-5075

Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators f…

Fix: after 5.0.9
Fix from $1,600 2015-09-29
Refbase MEDIUM 6.8
CVE-2015-6007

Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to hijack the authentic…

Fix: after 0.9.6
Fix from $1,600 2015-09-28
Data Manager MEDIUM 6.8
CVE-2015-6468

Cross-site request forgery (CSRF) vulnerability in Resource Data Management Data Manager before 2.2 allows remote attackers to hijack the authenticat…

Fix: after 2.1
Fix from $1,600 2015-09-26
Telepresence Server Software MEDIUM 6.8
CVE-2015-6304

Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Server software 3.0(2.24) allows remote attackers to hijack the authentication …

Mitigation only
Fix from $1,600 2015-09-24
Speedsurf 504an Firmware MEDIUM 6.8
CVE-2015-5991

Cross-site request forgery (CSRF) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmw…

Mitigation only
Fix from $1,600 2015-09-21
Almond 2015 Firmware MEDIUM 6.8
CVE-2015-2916

Cross-site request forgery (CSRF) vulnerability on Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with f…

Patch available
Fix from $1,600 2015-09-21
Open Semantic Framework MEDIUM 5.1
CVE-2015-7233

Cross-site request forgery (CSRF) vulnerability in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Import module is enabled, allows re…

Patch available
Fix from $1,600 2015-09-17
Openfire MEDIUM 6.8
CVE-2015-6973EPSS 65%

Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of …

No fix yet
Fix from $1,600 2015-09-16
Nibbleblog MEDIUM 6.8
CVE-2015-6966

Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack the authentication of administ…

Fix: after 4.0.4
Fix from $1,600 2015-09-16
Contact Form Generator MEDIUM 6.8
CVE-2015-6965

Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attacker…

Fix: after 2.0.1
Fix from $1,600 2015-09-16
Jsp\/mysql Administrador Web MEDIUM 6.8
CVE-2015-6944

Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for re…

No fix yet
Fix from $1,600 2015-09-15
Pixma Mg7500 Series Inkjet Printer MEDIUM 6.8
CVE-2015-5631

Cross-site request forgery (CSRF) vulnerability in the Remote UI on Canon PIXMA MG7500 printers allows remote attackers to hijack the authentication …

Mitigation only
Fix from $1,600 2015-09-11
Auto Exchanger MEDIUM 6.8
CVE-2015-6827

Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests th…

No fix yet
Fix from $1,600 2015-09-11
Cerb MEDIUM 6.8
CVE-2015-6545

Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrato…

Fix: after 7.0.3
Fix from $1,600 2015-09-03
Mediawiki HIGH 7.5
CVE-2015-6728

The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 does not perform token comparison …

Fix: after 1.23.9
Fix from $1,950 2015-09-01
Pligg Cms MEDIUM 6.8
CVE-2015-6655

Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for request…

No fix yet
Fix from $1,600 2015-08-31
Check Mk MEDIUM 6.8
CVE-2014-2330

Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authe…

Fix: after 1.2.3
Fix from $1,600 2015-08-31
Simatic S7 1200 Cpu Firmware HIGH 7.5
CVE-2015-5698

Cross-site request forgery (CSRF) vulnerability in the web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1.3 allows remote att…

Fix: after 4.1.2
Fix from $1,950 2015-08-30
Version Control Repository Manager MEDIUM 6.0
CVE-2015-5412

Cross-site request forgery (CSRF) vulnerability in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to hij…

Fix: after 7.4.0
Fix from $1,600 2015-08-26
Prime Infrastructure MEDIUM 6.8
CVE-2015-6262

Cross-site request forgery (CSRF) vulnerability in Cisco Prime Infrastructure 1.2(0.103) and 2.0(0.0) allows remote attackers to hijack the authentic…

Mitigation only
Fix from $1,600 2015-08-25
Drupal MEDIUM 6.8
CVE-2015-6660

The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF a…

Patch available
Fix from $1,600 2015-08-24
Ncs01 Firmware MEDIUM 6.8
CVE-2015-2905

Cross-site request forgery (CSRF) vulnerability on Actiontec GT784WN modems with firmware before NCS01-1.0.13 allows remote attackers to hijack the a…

Fix: after 1.0.12
Fix from $1,600 2015-08-23