Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Sametime Proxy Server And Web Client MEDIUM 6.8
CVE-2014-3015

Cross-site request forgery (CSRF) vulnerability in the Web player in IBM Sametime Proxy Server and Web Client 9.0 through 9.0.0.1 allows remote attac…

Mitigation only
Fix from $1,600 2014-05-26
Security Manager MEDIUM 6.8
CVE-2014-3267

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attackers to hijack the …

Fix: after 4.6
Fix from $1,600 2014-05-26
Krisonav MEDIUM 6.8
CVE-2013-2713

Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication…

Fix: after 3.0.1
Fix from $1,600 2014-05-23
Mail On Update MEDIUM 6.8
CVE-2013-2107

Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authent…

Fix: after 5.1.0
Fix from $1,600 2014-05-23
Search Everything MEDIUM 6.8
CVE-2014-3843

Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the auth…

Fix: after 8.1
Fix from $1,600 2014-05-22
Color Picker MEDIUM 6.8
CVE-2014-3845

Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the aut…

Fix: after 1.1
Fix from $1,600 2014-05-22
450tc2 Router Firmware MEDIUM 6.8
CVE-2014-3792

Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authent…

No fix yet
Fix from $1,600 2014-05-20
Dap 1150 Firmware MEDIUM 6.8
CVE-2014-3760

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP 1150 with firmware 1.2.94 allow remote attackers to hijack the authenticatio…

No fix yet
Fix from $1,600 2014-05-16
Infosphere Information Server Metadata Workbench MEDIUM 6.8
CVE-2014-0933

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Information Server Metadata Workbench 8.1 through 9.1 allows remote attackers to hi…

Mitigation only
Fix from $1,600 2014-05-16
Openx MEDIUM 6.8
CVE-2013-7376

Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to hijack the auth…

No fix yet
Fix from $1,600 2014-05-14
Wp125 MEDIUM 6.8
CVE-2013-2700

Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 for WordPress allows remote at…

Fix: after 1.4.9
Fix from $1,600 2014-05-14
Jenkins MEDIUM 6.8
CVE-2013-2034

Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and …

Fix: after 1.513
Fix from $1,600 2014-05-14
Omniauth Facebook MEDIUM 6.8
CVE-2013-4562

The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site reque…

Patch available
Fix from $1,600 2014-05-13
Openvpn Access Server MEDIUM 6.8
CVE-2013-2692

Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack th…

Fix: after 1.8.4
Fix from $1,600 2014-05-13
Wordpress Simple Paypal Shopping Cart MEDIUM 6.8
CVE-2013-2705

Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers …

Fix: after 3.5
Fix from $1,600 2014-05-13
Tao MEDIUM 6.8
CVE-2014-2989

Cross-site request forgery (CSRF) vulnerability in Open Assessment Technologies TAO 2.5.6 allows remote attackers to hijack the authentication of adm…

No fix yet
Fix from $1,600 2014-05-13
Confluence Server MEDIUM 6.8
CVE-2012-6342

Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication o…

No fix yet
Fix from $1,600 2014-05-13
Mediawiki MEDIUM 6.8
CVE-2014-3454

Cross-site request forgery (CSRF) vulnerability in Special:CreateCategory in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.…

Fix: after 1.19.9
Fix from $1,600 2014-05-12
Mediawiki MEDIUM 6.8
CVE-2014-3455

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) CreateProperty, (2) CreateTemplate, (3) CreateForm, and (4) CreateClass special…

Fix: after 1.19.9
Fix from $1,600 2014-05-12
Simplerisk MEDIUM 6.8
CVE-2013-5748

Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to hi…

Fix: after 20130915-001
Fix from $1,600 2014-05-12
Operational Decision Manager MEDIUM 6.0
CVE-2014-0944

Cross-site request forgery (CSRF) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, …

Mitigation only
Fix from $1,600 2014-05-09
Fortiweb MEDIUM 6.8
CVE-2014-3115

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before 5.2.0 allow remote attackers…

Fix: after 5.1.4
Fix from $1,600 2014-05-08
Broadband Access Center Telco Wireless Software MEDIUM 6.8
CVE-2014-2190

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wireless (aka BAC-TW) allows remo…

Mitigation only
Fix from $1,600 2014-05-07
Phplist MEDIUM 6.8
CVE-2014-2916

Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers to hijack…

Fix: after 3.0.5
Fix from $1,600 2014-05-05
Webex Meetings Server MEDIUM 6.8
CVE-2014-2186

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server allows remote attackers to hijack the authenticat…

Mitigation only
Fix from $1,600 2014-04-30
Neo4j MEDIUM 6.8
CVE-2013-7259

Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for r…

Mitigation only
Fix from $1,600 2014-04-29
Xcloner HIGH 7.6
CVE-2014-2579EPSS 6%

Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication …

Fix: after 3.5
Fix from $1,950 2014-04-25
Cm3 Acora Content Management System MEDIUM 6.8
CVE-2013-4726

Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other vers…

No fix yet
Fix from $1,600 2014-04-25
Revive Adserver MEDIUM 6.8
CVE-2013-5954

Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of adminis…

Fix: after 3.0.4
Fix from $1,600 2014-04-25
Debian Linux MEDIUM 6.8
CVE-2014-2327

Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users fo…

Fix: after 0.8.8b
Fix from $1,600 2014-04-23