Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Shopizer MEDIUM 6.8
CVE-2014-4964

Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users…

Fix: after 1.1.5
Fix from $1,600 2014-07-15
Algo Credit Limits MEDIUM 6.8
CVE-2014-0864

Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0…

No fix yet
Fix from $1,600 2014-07-07
Simple Share Buttons Adder MEDIUM 6.8
CVE-2014-4717

Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers t…

Fix: after 4.4
Fix from $1,600 2014-07-03
Lunar Cms MEDIUM 6.8
CVE-2014-4718

Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administr…

Fix: after 3.3
Fix from $1,600 2014-07-03
Kanboard MEDIUM 6.8
CVE-2014-3920

Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of administrators for r…

Fix: after 1.0.6
Fix from $1,600 2014-07-03
Twg87ouir MEDIUM 6.8
CVE-2014-4716

Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authentication of unspecified victims for …

No fix yet
Fix from $1,600 2014-07-03
Piwigo MEDIUM 6.8
CVE-2014-4614

Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrato…

Fix: after 2.6.1
Fix from $1,600 2014-07-02
Web Kyukincho MEDIUM 6.8
CVE-2014-3881

Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authentication of …

Mitigation only
Fix from $1,600 2014-06-28
Jw Player For Flash \& Html5 Video Plugin MEDIUM 6.8
CVE-2014-4030

Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authenticati…

Fix: after 2.1.3
Fix from $1,600 2014-06-25
Login Rebuilder MEDIUM 6.8
CVE-2014-3882

Cross-site request forgery (CSRF) vulnerability in the Login rebuilder plugin before 1.2.0 for WordPress allows remote attackers to hijack the authen…

Fix: after 1.1.3
Fix from $1,600 2014-06-25
Zxv10 W300 Firmware MEDIUM 6.8
CVE-2014-4155

Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the a…

No fix yet
Fix from $1,600 2014-06-19
Dolphin MEDIUM 6.8
CVE-2014-4333

Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the aut…

Fix: after 7.1.4
Fix from $1,600 2014-06-19
Arris Sbg901 MEDIUM 6.8
CVE-2014-3778

Multiple cross-site request forgery (CSRF) vulnerabilities in goform/RgDdns in ARRIS (formerly Motorola) SBG901 SURFboard Wireless Cable Modem allow …

No fix yet
Fix from $1,600 2014-06-19
Jp1\/performance Management Manager Web Option MEDIUM 6.8
CVE-2014-4188

Cross-site request forgery (CSRF) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP1/Performance Management - Ma…

Mitigation only
Fix from $1,600 2014-06-17
P 660hw MEDIUM 6.8
CVE-2014-4162

Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authenti…

No fix yet
Fix from $1,600 2014-06-16
Featured Comments MEDIUM 6.8
CVE-2014-4163

Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the a…

No fix yet
Fix from $1,600 2014-06-16
Member Approval MEDIUM 6.8
CVE-2014-3850

Cross-site request forgery (CSRF) vulnerability in the Member Approval plugin 131109 for WordPress allows remote attackers to hijack the authenticati…

No fix yet
Fix from $1,600 2014-06-11
Connections MEDIUM 6.0
CVE-2014-0929

Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows remote authenticated users to…

Fix: after 3.0.1.1
Fix from $1,600 2014-06-08
Security Identity Manager MEDIUM 6.0
CVE-2014-0961

Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Id…

Mitigation only
Fix from $1,600 2014-06-08
Owncloud MEDIUM 6.8
CVE-2014-3836

Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud Server before 6.0.3 allow remote attackers to hijack the authentication of use…

Fix: after 6.0.2
Fix from $1,600 2014-06-04
Webui MEDIUM 6.8
CVE-2014-2946

Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.8…

Mitigation only
Fix from $1,600 2014-06-02
Contextual Related Posts MEDIUM 6.8
CVE-2013-2710

Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows remote attackers to hijack t…

Fix: after 1.8.6
Fix from $1,600 2014-06-02
Related Posts MEDIUM 6.8
CVE-2013-3257

Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote attackers to hijack the authenti…

Fix: after 2.7.1
Fix from $1,600 2014-06-02
Digg Digg MEDIUM 6.8
CVE-2013-3258

Cross-site request forgery (CSRF) vulnerability in he Digg Digg plugin before 5.3.5 for WordPress allows remote attackers to hijack the authenticatio…

Fix: after 5.3.4
Fix from $1,600 2014-06-02
Related Posts MEDIUM 6.8
CVE-2013-3476

Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows remote attackers to hijack th…

Fix: after 2.6
Fix from $1,600 2014-06-02
Sharetronix MEDIUM 6.8
CVE-2014-3414

Cross-site request forgery (CSRF) vulnerability in Sharetronix before 3.4 allows remote attackers to hijack the authentication of administrators for …

Fix: after 3.3
Fix from $1,600 2014-05-29
Calendar MEDIUM 6.8
CVE-2013-2698

Cross-site request forgery (CSRF) vulnerability in the Calendar plugin before 1.3.3 for WordPress allows remote attackers to hijack the authenticatio…

Fix: after 1.3.2
Fix from $1,600 2014-05-27
Related Posts MEDIUM 6.8
CVE-2013-3477

Cross-site request forgery (CSRF) vulnerability in the Related Posts by Zemanta plugin before 1.3.2 for WordPress allows remote attackers to hijack t…

Fix: after 1.3.1
Fix from $1,600 2014-05-27
Moodle MEDIUM 6.8
CVE-2014-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x bef…

Fix: after 2.3.11
Fix from $1,600 2014-05-27
Usercake MEDIUM 6.8
CVE-2014-3866

Multiple cross-site request forgery (CSRF) vulnerabilities in user_settings.php in Usercake 2.0.2 and earlier allow remote attackers to hijack the au…

Fix: after 2.0.2
Fix from $1,600 2014-05-26