Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Fiverrscript MEDIUM 6.8
CVE-2015-4677

Cross-site request forgery (CSRF) vulnerability in FiverrScript (aka Fiverr Script) 7.2 allows remote attackers to hijack the authentication of admin…

No fix yet
Fix from $1,600 2015-06-19
Clickheat MEDIUM 6.8
CVE-2015-4659

Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators …

Fix: after 1.1.4
Fix from $1,600 2015-06-18
Wp Smiley MEDIUM 6.8
CVE-2015-4140

Cross-site request forgery (CSRF) vulnerability in the WP Smiley plugin 1.4.1 for WordPress allows remote attackers to hijack the authentication of e…

No fix yet
Fix from $1,600 2015-06-18
Vesta Control Panel MEDIUM 6.8
CVE-2015-2861

Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack the authentication of arbitr…

Fix: after 0.9.8-12
Fix from $1,600 2015-06-18
Omniswitch Firmware MEDIUM 6.8
CVE-2015-2805

Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent Omni…

Fix: after 8.1.1.r01
Fix from $1,600 2015-06-16
Ispconfig MEDIUM 6.8
CVE-2015-4119

Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) a…

Fix: after 3.0.5.4
Fix from $1,600 2015-06-15
Node Template MEDIUM 6.8
CVE-2015-4397

Cross-site request forgery (CSRF) vulnerability in the Node Template module for Drupal allows remote attackers to hijack the authentication of users …

Mitigation only
Fix from $1,600 2015-06-15
Keyword Research MEDIUM 5.1
CVE-2015-4396

Multiple cross-site request forgery (CSRF) vulnerabilities in the Keyword Research module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to…

Patch available
Fix from $1,600 2015-06-15
Civicrm Private Report MEDIUM 6.8
CVE-2015-4391

Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal all…

Patch available
Fix from $1,600 2015-06-15
User Import MEDIUM 6.8
CVE-2015-4390

Multiple cross-site request forgery (CSRF) vulnerabilities in the User Import module 6.x-4.x before 6.x-4.4 and 7.x-2.x before 7.x-2.3 for Drupal all…

Patch available
Fix from $1,600 2015-06-15
Decisions MEDIUM 6.8
CVE-2015-4383

Cross-site request forgery (CSRF) vulnerability in the Decisions module for Drupal allows remote attackers to hijack the authentication of arbitrary …

Patch available
Fix from $1,600 2015-06-15
Invoice MEDIUM 6.8
CVE-2015-4382

Multiple cross-site request forgery (CSRF) vulnerabilities in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allow r…

Patch available
Fix from $1,600 2015-06-15
Webform Multiple File Upload MEDIUM 6.8
CVE-2015-4379

Cross-site request forgery (CSRF) vulnerability in the Webform Multiple File Upload module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drup…

Patch available
Fix from $1,600 2015-06-15
Campaign Monitor MEDIUM 6.8
CVE-2015-4364

Multiple cross-site request forgery (CSRF) vulnerabilities in includes/campaignmonitor_lists.admin.inc in the Campaign Monitor module 7.x-1.0 for Dru…

Patch available
Fix from $1,600 2015-06-15
Tracking Code MEDIUM 6.8
CVE-2015-4362

Cross-site request forgery (CSRF) vulnerability in tracking_code.admin.inc in the Tracking Code module 7.x-1.x before 7.x-1.6 for Drupal allows remot…

Patch available
Fix from $1,600 2015-06-15
Registration Codes MEDIUM 6.8
CVE-2015-4361

Cross-site request forgery (CSRF) vulnerability in the Registration codes module before 6.x-1.6 for Drupal allows remote attackers to hijack the auth…

Fix: after 6.x-1.x-dev
Fix from $1,600 2015-06-15
Registration Codes MEDIUM 6.8
CVE-2015-4360

Cross-site request forgery (CSRF) vulnerability in the Registration codes module before 6.x-1.6, 6.x-2.x before 6.x-2.8, and 7.x-1.x before 7.x-1.2 f…

Fix: after 6.x-1.x-dev
Fix from $1,600 2015-06-15
Watchdog Aggregator MEDIUM 6.8
CVE-2015-4355

Cross-site request forgery (CSRF) vulnerability in the Watchdog Aggregator module for Drupal allows remote attackers to hijack the authentication of …

Mitigation only
Fix from $1,600 2015-06-15
Custom Sitemap MEDIUM 5.8
CVE-2015-4353

Cross-site request forgery (CSRF) vulnerability in the Custom Sitemap module for Drupal allows remote attackers to hijack the authentication of admin…

Mitigation only
Fix from $1,600 2015-06-15
Web Dorado Spider Video Player MEDIUM 5.8
CVE-2015-4352

Cross-site request forgery (CSRF) vulnerability in the Spider Video Player module for Drupal allows remote attackers to hijack the authentication of …

Mitigation only
Fix from $1,600 2015-06-15
Spider Catalog MEDIUM 6.8
CVE-2015-4350

Multiple cross-site request forgery (CSRF) vulnerabilities in the Spider Catalog module for Drupal allow remote attackers to hijack the authenticatio…

Mitigation only
Fix from $1,600 2015-06-15
Spider Contacts MEDIUM 5.8
CVE-2015-4349

Cross-site request forgery (CSRF) vulnerability in the Spider Contacts module for Drupal allows remote attackers to hijack the authentication of admi…

Mitigation only
Fix from $1,600 2015-06-15
Milkystep Light MEDIUM 6.8
CVE-2015-2954

Cross-site request forgery (CSRF) vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers …

Fix: after 1.82
Fix from $1,600 2015-06-13
Wing Ftp Server MEDIUM 6.8
CVE-2015-4108

Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of adm…

Fix: after 4.4.6
Fix from $1,600 2015-06-10
Air MEDIUM 6.8
CVE-2015-3096

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.172
Fix from $1,600 2015-06-10
Exchange Server MEDIUM 6.8
CVE-2015-1771EPSS 6%

Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote a…

Mitigation only
Fix from $1,600 2015-06-10
Encrypted Contact Form MEDIUM 6.8
CVE-2015-4010

Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows remote attackers to hijack the a…

Fix: 1.1+
Fix from $1,600 2015-06-09
Ektron Content Management System MEDIUM 5.8
CVE-2015-3624

Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) befor…

Fix: after 9.1
Fix from $1,600 2015-06-09
Manageengine Netflow Analyzer MEDIUM 6.8
CVE-2015-2961

Cross-site request forgery (CSRF) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers to hijack the authentication…

Patch available
Fix from $1,600 2015-06-09
442sr Os MEDIUM 6.8
CVE-2015-3950

Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hijack the authentication of adm…

Mitigation only
Fix from $1,600 2015-06-05