Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Websphere Portal MEDIUM 6.8
CVE-2014-6214

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote attackers to h…

Patch available
Fix from $1,600 2015-03-13
Contact Form Db MEDIUM 6.8
CVE-2015-1874

Cross-site request forgery (CSRF) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plugin before 2.8.32 for W…

Patch available
Fix from $1,600 2015-03-09
All In One Wordpress Security And Firewall MEDIUM 6.8
CVE-2015-0895

Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to…

Fix: after 3.8.9
Fix from $1,600 2015-03-07
Application Networking Manager MEDIUM 6.8
CVE-2015-0651

Cross-site request forgery (CSRF) vulnerability in the web GUI in Cisco Application Networking Manager (ANM), and Device Manager (DM) on Cisco 4710 A…

Mitigation only
Fix from $1,600 2015-02-27
Crossslide Jquery MEDIUM 6.8
CVE-2015-2089

Multiple cross-site request forgery (CSRF) vulnerabilities in the CrossSlide jQuery (crossslide-jquery-plugin-for-wordpress) plugin 2.0.5 for WordPre…

No fix yet
Fix from $1,600 2015-02-26
Easy Social Icons MEDIUM 6.8
CVE-2015-2084

Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the auth…

Fix: after 1.2.2
Fix from $1,600 2015-02-25
Cms MEDIUM 6.8
CVE-2015-2083

Cross-site request forgery (CSRF) vulnerability in Ilch CMS allows remote attackers to hijack the authentication of administrators for requests that …

No fix yet
Fix from $1,600 2015-02-25
Dcs 931l Firmware MEDIUM 6.8
CVE-2015-2048

Cross-site request forgery (CSRF) vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote attackers to hijack the authenticatio…

Fix: after 1.04
Fix from $1,600 2015-02-23
Acobot Live Chat \& Contact Form MEDIUM 6.8
CVE-2015-2039

Multiple cross-site request forgery (CSRF) vulnerabilities in the Acobot Live Chat & Contact Form plugin 2.0 for WordPress allow remote attackers to …

No fix yet
Fix from $1,600 2015-02-20
Image Metadata Cruncher MEDIUM 6.8
CVE-2015-1614

Multiple cross-site request forgery (CSRF) vulnerabilities in the Image Metadata Cruncher plugin for WordPress allow remote attackers to hijack the a…

No fix yet
Fix from $1,600 2015-02-19
Fat Free Crm MEDIUM 6.8
CVE-2015-1585

Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token,…

Fix: after 0.13.5
Fix from $1,600 2015-02-19
Ovirt Engine MEDIUM 6.8
CVE-2014-0151

Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for …

Fix: after 3.5.0
Fix from $1,600 2015-02-13
Prime Infrastructure MEDIUM 6.8
CVE-2014-2152

Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote attackers to hijack the authentic…

Mitigation only
Fix from $1,600 2015-02-12
Mobile Domain MEDIUM 6.8
CVE-2015-1581

Multiple cross-site request forgery (CSRF) vulnerabilities in the Mobile Domain plugin 1.5.2 for WordPress allow remote attackers to hijack the authe…

No fix yet
Fix from $1,600 2015-02-11
Redirection MEDIUM 6.8
CVE-2015-1580

Multiple cross-site request forgery (CSRF) vulnerabilities in the Redirection Page plugin 1.2 for WordPress allow remote attackers to hijack the auth…

No fix yet
Fix from $1,600 2015-02-11
Efront MEDIUM 6.8
CVE-2015-1559

Multiple cross-site request forgery (CSRF) vulnerabilities in administrator.php in Epignosis eFront Open Source Edition before 3.6.15.3 build 18022 a…

Fix: after 3.6.15.2
Fix from $1,600 2015-02-10
Phpbb MEDIUM 6.8
CVE-2015-1432

The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote a…

Fix: after 3.0.12
Fix from $1,600 2015-02-10
Gd Infinite Scroll MEDIUM 6.8
CVE-2015-1568

Cross-site request forgery (CSRF) vulnerability in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote attackers to hijack the auth…

Fix: after 7.x-1.3
Fix from $1,600 2015-02-09
Owncloud MEDIUM 6.8
CVE-2014-9041

The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 does not validate CSRF…

Fix: after 5.0.17
Fix from $1,600 2015-02-04
Manageengine Desktop Central MEDIUM 6.8
CVE-2014-9331

Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authe…

Fix: after 9.0
Fix from $1,600 2015-02-04
Webex Meetings Server MEDIUM 6.8
CVE-2015-0596

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authenti…

Fix: after 1.5
Fix from $1,600 2015-02-02
Rt N66u Firmware MEDIUM 6.8
CVE-2014-7270

Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firm…

Fix: after 3.0.0.4.378.3754
Fix from $1,600 2015-02-01
Gecko Cms MEDIUM 6.8
CVE-2015-1424

Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote attackers to hijack the authentication of administrators for r…

No fix yet
Fix from $1,600 2015-01-29
Ferretcms MEDIUM 6.8
CVE-2015-1374

Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack the authentication …

No fix yet
Fix from $1,600 2015-01-27
Unified Communications Domain Manager MEDIUM 6.8
CVE-2015-0588

Cross-site request forgery (CSRF) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to hijack the authen…

Mitigation only
Fix from $1,600 2015-01-15
Webmail MEDIUM 6.8
CVE-2014-9587

Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of u…

Fix: after 1.0.3
Fix from $1,600 2015-01-15
Pods MEDIUM 6.8
CVE-2014-7957

Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentic…

Fix: after 2.4.3
Fix from $1,600 2015-01-15
Firefox MEDIUM 6.8
CVE-2014-8638

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2…

Fix: after 34.0.5
Fix from $1,600 2015-01-14
Savsoft Quiz MEDIUM 6.8
CVE-2014-100025

Cross-site request forgery (CSRF) vulnerability in index.php/user_data/insert_user in Savsoft Quiz allows remote attackers to hijack the authenticati…

No fix yet
Fix from $1,600 2015-01-13
Dap 1360 Firmware MEDIUM 6.8
CVE-2014-10027

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 router with firmware 2.5.4 and earlier allow remote attackers to hijack…

Fix: after 2.5.4
Fix from $1,600 2015-01-13