Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
N900 Firmware MEDIUM 6.8
CVE-2013-3086

Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hijack the authentication of adm…

No fix yet
Fix from $1,600 2014-09-29
N300 Firmware MEDIUM 6.8
CVE-2013-3089

Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication o…

No fix yet
Fix from $1,600 2014-09-29
Websphere Application Server MEDIUM 6.0
CVE-2014-4816

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 bef…

Patch available
Fix from $1,600 2014-09-23
Cacheguardos MEDIUM 6.8
CVE-2014-4865

Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authenticatio…

Mitigation only
Fix from $1,600 2014-09-10
Initiate Master Data Service MEDIUM 6.0
CVE-2014-4785

Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.09…

Patch available
Fix from $1,600 2014-09-10
Rational Rhapsody Design Manager MEDIUM 6.0
CVE-2014-3037

Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager b…

Fix: after 4.06
Fix from $1,600 2014-09-10
Initiate Master Data Service MEDIUM 6.8
CVE-2014-4783

Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.09…

Patch available
Fix from $1,600 2014-09-10
Network Security Manager MEDIUM 6.8
CVE-2014-2390

Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) before 6.1.15.39 7.1.5.x befor…

Fix: 6.1.15.39 / 7.1.5.15+
Fix from $1,600 2014-08-29
Smartcloud Control Desk MEDIUM 6.0
CVE-2014-3024

Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5.0.6 and Maximo Asset Manageme…

Mitigation only
Fix from $1,600 2014-08-29
Emptoris Spend Analysis MEDIUM 6.8
CVE-2014-3061

Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10…

Mitigation only
Fix from $1,600 2014-08-26
Mailpoet Newsletters MEDIUM 6.8
CVE-2014-3907

Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote att…

Fix: after 2.6.10
Fix from $1,600 2014-08-26
Emptoris Spend Analysis MEDIUM 6.0
CVE-2014-3040

Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 1…

Mitigation only
Fix from $1,600 2014-08-26
Innovaphone Pbx MEDIUM 6.8
CVE-2014-5335

Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authenticat…

Fix: after 10.00
Fix from $1,600 2014-08-25
Service Manager MEDIUM 6.8
CVE-2014-2633

Cross-site request forgery (CSRF) vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to hijack t…

Mitigation only
Fix from $1,600 2014-08-23
Mediawiki MEDIUM 6.8
CVE-2014-5241

The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 accep…

Fix: after 1.19.17
Fix from $1,600 2014-08-22
Rsa Archer Egrc MEDIUM 6.8
CVE-2014-0641

Cross-site request forgery (CSRF) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to hijack the authenticatio…

Mitigation only
Fix from $1,600 2014-08-20
Digital Assets Manager MEDIUM 6.8
CVE-2014-2518

Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hi…

Mitigation only
Fix from $1,600 2014-08-20
Disqus Comment System MEDIUM 6.8
CVE-2014-5346

Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow remote attackers to hijack th…

No fix yet
Fix from $1,600 2014-08-19
Disqus Comment System MEDIUM 6.8
CVE-2014-5347

Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hi…

Fix: after 2.75
Fix from $1,600 2014-08-19
Debian Linux MEDIUM 6.8
CVE-2014-5204

wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce ar…

Fix: after 3.9.1
Fix from $1,600 2014-08-18
WordPress MEDIUM 6.8
CVE-2014-5205

wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, whic…

Fix: after 3.9.1
Fix from $1,600 2014-08-18
Infosphere Master Data Management MEDIUM 6.8
CVE-2014-0969

Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x b…

Patch available
Fix from $1,600 2014-08-17
Zpanel MEDIUM 6.8
CVE-2012-5683

Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack the authentication of admini…

Fix: after 10.0.1
Fix from $1,600 2014-08-14
Wordpress File Upload MEDIUM 6.8
CVE-2014-5199

Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attacke…

Fix: after 2.4.1
Fix from $1,600 2014-08-12
Pyplate MEDIUM 6.8
CVE-2014-3854

Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication of adminis…

No fix yet
Fix from $1,600 2014-08-07
Acmailer MEDIUM 6.8
CVE-2014-3896

Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote …

Fix: 3.8.17 / 3.9.10+
Fix from $1,600 2014-07-29
Vx MEDIUM 6.8
CVE-2014-2974

Cross-site request forgery (CSRF) vulnerability in php/user_account.php in Silver Peak VX through 6.2.4 allows remote attackers to hijack the authent…

Fix: after 6.2.4
Fix from $1,600 2014-07-28
Webex Meetings Server MEDIUM 6.8
CVE-2014-3305

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers t…

Fix: after 1.5
Fix from $1,600 2014-07-26
Omeka MEDIUM 6.8
CVE-2014-5100

Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrator…

Fix: after 2.2
Fix from $1,600 2014-07-25
Ns Series System Program Firmware MEDIUM 6.0
CVE-2014-2369

Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allo…

Mitigation only
Fix from $1,600 2014-07-24