Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Contact Form Fields MEDIUM 6.8
CVE-2015-3363

Cross-site request forgery (CSRF) vulnerability in the Contact Form Fields module before 6.x-2.3 for Drupal allows remote attackers to hijack the aut…

Fix: after 6.x-2.2
Fix from $1,600 2015-04-21
Tadaa\! MEDIUM 6.8
CVE-2015-3356

Multiple cross-site request forgery (CSRF) vulnerabilities in the Tadaa! module before 7.x-1.4 for Drupal allow remote attackers to hijack the authen…

Fix: after 7.x-1.3
Fix from $1,600 2015-04-21
Wishlist MEDIUM 5.8
CVE-2015-3354

Cross-site request forgery (CSRF) vulnerability in the Wishlist module before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote attackers t…

Fix: after 6.x-2.6
Fix from $1,600 2015-04-21
Batch Jobs MEDIUM 6.8
CVE-2015-3355

Multiple cross-site request forgery (CSRF) vulnerabilities in the Batch Jobs module before 7.x-1.2 for Drupal allow remote attackers to hijack the au…

Fix: after 7.x-1.1
Fix from $1,600 2015-04-21
Jammer MEDIUM 6.8
CVE-2015-3352

Multiple cross-site request forgery (CSRF) vulnerabilities in the Jammer module before 6.x-1.8 and 7.x-1.x before 7.x-1.4 for Drupal allow remote att…

Fix: after 6.x-1.7
Fix from $1,600 2015-04-21
Log Watcher MEDIUM 6.8
CVE-2015-3351

Multiple cross-site request forgery (CSRF) vulnerabilities in the Log Watcher module before 6.x-1.2 for Drupal allow remote attackers to hijack the a…

Fix: after 6.x-1.x-dev
Fix from $1,600 2015-04-21
Todo Filter MEDIUM 6.8
CVE-2015-3350

Cross-site request forgery (CSRF) vulnerability in the Todo Filter module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attacker…

Fix: after 6.x-1.0
Fix from $1,600 2015-04-21
Htaccess MEDIUM 6.8
CVE-2015-3349

Multiple cross-site request forgery (CSRF) vulnerabilities in the Htaccess module before 7.x-2.3 for Drupal allow remote attackers to hijack the auth…

Fix: after 7.x-2.2
Fix from $1,600 2015-04-21
Cloudwords For Multilingual MEDIUM 6.8
CVE-2015-3347

Cross-site request forgery (CSRF) vulnerability in the Cloudwords for Multilingual Drupal module before 7.x-2.3 for Drupal allows remote attackers to…

Fix: after 7.x-2.2
Fix from $1,600 2015-04-21
Opac MEDIUM 6.8
CVE-2015-3343

Cross-site request forgery (CSRF) vulnerability in the OPAC module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of …

Fix: after 7.x-2.0
Fix from $1,600 2015-04-21
Landesk Management Suite MEDIUM 6.8
CVE-2014-5361

Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote attackers to hijack the authentic…

Fix: after 9.6
Fix from $1,600 2015-04-21
Searchblox HIGH 8.8
CVE-2015-0970

Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentication of arbitrary users.

Fix: after 8.1
Fix from $1,950 2015-04-18
Secure Access Control Server Solution Engine MEDIUM 6.8
CVE-2015-0700

Cross-site request forgery (CSRF) vulnerability in the Dashboard page in the monitoring-and-report section in Cisco Secure Access Control Server Solu…

Mitigation only
Fix from $1,600 2015-04-17
Checkuser MEDIUM 6.8
CVE-2015-2940

Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of cert…

Patch available
Fix from $1,600 2015-04-13
Pfsense MEDIUM 6.8
CVE-2015-2295EPSS 66%

Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attacker…

Fix: after 2.2
Fix from $1,600 2015-04-10
Bblog MEDIUM 6.8
CVE-2015-0905

Cross-site request forgery (CSRF) vulnerability in bBlog allows remote attackers to hijack the authentication of arbitrary users.

Mitigation only
Fix from $1,600 2015-04-08
Netscaler MEDIUM 6.8
CVE-2015-2838

Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authe…

No fix yet
Fix from $1,600 2015-04-03
Ab Google Map Travel MEDIUM 6.8
CVE-2015-2755

Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attacker…

Fix: after 3.4
Fix from $1,600 2015-04-01
Firefox MEDIUM 6.8
CVE-2015-0807

The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x …

Fix: after 36.0.4
Fix from $1,600 2015-04-01
442sr Os MEDIUM 6.8
CVE-2015-0985

Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hijack the authentication of adm…

Mitigation only
Fix from $1,600 2015-03-31
V Series Appliances MEDIUM 6.8
CVE-2015-2770

Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote attackers …

Fix: after 7.7
Fix from $1,600 2015-03-27
Triton Ap Email MEDIUM 6.8
CVE-2015-2769

Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allow remote …

Fix: after 7.8.3
Fix from $1,600 2015-03-27
Data Loss Prevention Endpoint MEDIUM 6.8
CVE-2015-2759

Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hot…

Fix: after 9.3.400
Fix from $1,600 2015-03-27
Cs Cart MEDIUM 6.8
CVE-2015-2701

Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that chan…

No fix yet
Fix from $1,600 2015-03-25
Rational Clearquest MEDIUM 6.8
CVE-2014-8925

Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.…

Patch available
Fix from $1,600 2015-03-25
Genixcms MEDIUM 6.8
CVE-2015-2680

Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administr…

Fix: after 0.0.1
Fix from $1,600 2015-03-23
Rt G32 Firmware MEDIUM 6.8
CVE-2015-2676

Cross-site request forgery (CSRF) vulnerability in the ASUS RT-G32 routers with firmware 2.0.2.6 and 2.0.3.2 allows remote attackers to hijack the au…

No fix yet
Fix from $1,600 2015-03-23
Routeros MEDIUM 6.8
CVE-2015-2350

Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administ…

Fix: after 5.0
Fix from $1,600 2015-03-19
Mybb MEDIUM 6.8
CVE-2015-2334

Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attac…

Fix: after 1.8.3
Fix from $1,600 2015-03-18
Wordpress Seo MEDIUM 6.8
CVE-2015-2293

Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.…

Fix: after 1.5.6
Fix from $1,600 2015-03-17