Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Wpcommenttwit MEDIUM 6.8
CVE-2014-9340

Multiple cross-site request forgery (CSRF) vulnerabilities in the wpCommentTwit plugin 0.5 and earlier for WordPress allow remote attackers to hijack…

Fix: after 0.5
Fix from $1,600 2014-12-19
Spnbabble MEDIUM 6.8
CVE-2014-9339

Multiple cross-site request forgery (CSRF) vulnerabilities in the SPNbabble plugin 1.4.1 and earlier for WordPress allow remote attackers to hijack t…

No fix yet
Fix from $1,600 2014-12-19
Mikiurl Wordpress Eklentisi MEDIUM 6.8
CVE-2014-9337

Multiple cross-site request forgery (CSRF) vulnerabilities in the Mikiurl Wordpress Eklentisi plugin 2.0 and earlier for WordPress allow remote attac…

Fix: after 2.0
Fix from $1,600 2014-12-19
O2tweet MEDIUM 6.8
CVE-2014-9338

Multiple cross-site request forgery (CSRF) vulnerabilities in the O2Tweet plugin 0.0.4 and earlier for WordPress allow remote attackers to hijack the…

Fix: after 0.0.4
Fix from $1,600 2014-12-19
Itwitter MEDIUM 6.8
CVE-2014-9336

Multiple cross-site request forgery (CSRF) vulnerabilities in the iTwitter plugin 0.04 and earlier for WordPress allow remote attackers to hijack the…

Fix: after 0.04
Fix from $1,600 2014-12-19
Dandyid Services MEDIUM 6.8
CVE-2014-9335

Multiple cross-site request forgery (CSRF) vulnerabilities in the DandyID Services plugin 1.5.9 and earlier for WordPress allow remote attackers to h…

Fix: after 1.5.9
Fix from $1,600 2014-12-19
Security Access Manager For Web MEDIUM 6.8
CVE-2014-6077

Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x be…

Mitigation only
Fix from $1,600 2014-12-18
Touchstone Tg862g\/ct Firmware MEDIUM 6.8
CVE-2014-5437

Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow…

Fix: after 7.6.59s.ct
Fix from $1,600 2014-12-17
Release Automation MEDIUM 6.8
CVE-2014-8246

Cross-site request forgery (CSRF) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote atta…

Fix: after 4.7.1
Fix from $1,600 2014-12-16
Zenoss Core MEDIUM 6.8
CVE-2014-9385

Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbitrary use…

Mitigation only
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 6.8
CVE-2014-6253

Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hijack the authentication of arb…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Websphere Datapower Xc10 Appliance Firmware MEDIUM 6.0
CVE-2014-3058

Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated user…

Mitigation only
Fix from $1,600 2014-12-11
Struts MEDIUM 6.8
CVE-2014-7809

Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mecha…

No fix yet
Fix from $1,600 2014-12-10
Snowfox Content Management System MEDIUM 6.8
CVE-2014-9344

Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authentication of administrators f…

Fix: after 1.0
Fix from $1,600 2014-12-08
Alfresco MEDIUM 6.8
CVE-2014-9300

Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Communit…

Fix: after 5.0.a
Fix from $1,600 2014-12-07
Cm Download Manager MEDIUM 6.8
CVE-2014-9129

Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers t…

Fix: after 2.0.6
Fix from $1,600 2014-12-05
Modx Revolution MEDIUM 6.8
CVE-2014-8773

MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CS…

No fix yet
Fix from $1,600 2014-12-03
X3 Cms MEDIUM 6.8
CVE-2014-8771

Multiple cross-site request forgery (CSRF) vulnerabilities in the admin area in X3 CMS 0.5.1 and 0.5.1.1 allow remote attackers to hijack the authent…

No fix yet
Fix from $1,600 2014-12-03
Xepan Cms MEDIUM 6.8
CVE-2014-8429

Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows remote attackers to hijack t…

Fix: after 1.0.1
Fix from $1,600 2014-11-28
Qradar Vulnerability Manager MEDIUM 6.8
CVE-2014-4829

Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch…

Patch available
Fix from $1,600 2014-11-28
Openvpn Access Server MEDIUM 6.8
CVE-2014-9104

Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow …

Fix: after 1.5.6
Fix from $1,600 2014-11-26
Skadate Lite MEDIUM 6.8
CVE-2014-9101

Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attac…

No fix yet
Fix from $1,600 2014-11-26
Whydowork Adsense MEDIUM 6.8
CVE-2014-9099

Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authenticatio…

No fix yet
Fix from $1,600 2014-11-26
WordPress MEDIUM 6.8
CVE-2014-9033

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authe…

Patch available
Fix from $1,600 2014-11-25
Moodle MEDIUM 6.8
CVE-2014-7838

Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and …

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Moodle MEDIUM 6.8
CVE-2014-7836

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.…

Fix: after 2.4.11
Fix from $1,600 2014-11-24
E5180s 22 Firmware MEDIUM 6.8
CVE-2014-5395

Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R…

No fix yet
Fix from $1,600 2014-11-21
Zxdsl 831cii MEDIUM 6.8
CVE-2014-9027

Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators …

No fix yet
Fix from $1,600 2014-11-20
Zxdsl MEDIUM 6.8
CVE-2014-9019

Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators …

No fix yet
Fix from $1,600 2014-11-20
Xprintserver MEDIUM 6.8
CVE-2014-9003

Cross-site request forgery (CSRF) vulnerability in Lantronix xPrintServer allows remote attackers to hijack the authentication of administrators for …

No fix yet
Fix from $1,600 2014-11-20