Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Imagecms MEDIUM 6.8
CVE-2013-7334

Cross-site request forgery (CSRF) vulnerability in ImageCMS before 4.2 allows remote attackers to hijack the authentication of administrators for req…

Fix: after 4.0.0
Fix from $1,600 2014-03-11
Netscaler Application Delivery Controller Firmware MEDIUM 6.8
CVE-2013-6942

Cross-site request forgery (CSRF) vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.…

Mitigation only
Fix from $1,600 2014-03-11
Dimensions Cm MEDIUM 6.8
CVE-2014-0336

Cross-site request forgery (CSRF) vulnerability in the web client in Serena Dimensions CM 12.2 build 7.199.0 allows remote attackers to hijack the au…

Mitigation only
Fix from $1,600 2014-03-06
Unified Communications Manager MEDIUM 6.8
CVE-2014-0740

Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component …

Fix: after 10.0
Fix from $1,600 2014-02-27
Unified Contact Center Express Editor Software MEDIUM 6.8
CVE-2014-0745

Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability subsystem in Cisco Unified Contact Center Express (Unified CCX) allows …

Mitigation only
Fix from $1,600 2014-02-27
Service Manager MEDIUM 6.8
CVE-2013-6202

Multiple cross-site request forgery (CSRF) vulnerabilities in HP Service Manager 9.30, 9.31, 9.32, and 9.33 allow remote attackers to hijack the auth…

Mitigation only
Fix from $1,600 2014-02-24
Unified Communications Manager MEDIUM 6.8
CVE-2014-0736

Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Unified Communications Manager …

Fix: after 10.0
Fix from $1,600 2014-02-20
Firefox MEDIUM 6.8
CVE-2013-6167

Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows re…

Fix: after 27.0
Fix from $1,600 2014-02-15
Chrome MEDIUM 6.8
CVE-2013-6166

Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remot…

Fix: after 28.0.1500.95
Fix from $1,600 2014-02-15
Phpmyfaq MEDIUM 6.8
CVE-2014-0813

Cross-site request forgery (CSRF) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to hijack the authentication of arbitrary users for …

Fix: after 2.8.5
Fix from $1,600 2014-02-14
Command School Student Management System MEDIUM 6.8
CVE-2014-1915

Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the a…

No fix yet
Fix from $1,600 2014-02-07
Dap 2253 Firmware MEDIUM 6.8
CVE-2013-7320

Cross-site request forgery (CSRF) vulnerability in D-Link DAP-2253 Access Point (Rev. A1) with firmware before 1.30 allows remote attackers to hijack…

Fix: after 1.26rc55
Fix from $1,600 2014-02-06
Nexpose MEDIUM 6.8
CVE-2012-6493

Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers to hijack the authentication …

Fix: after 5.5.3
Fix from $1,600 2014-02-04
Tew 812dru Firmware MEDIUM 6.8
CVE-2013-3098

Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 allow remote attackers to hijac…

No fix yet
Fix from $1,600 2014-02-04
Otrs MEDIUM 6.8
CVE-2014-1694

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) CustomerPreferences.pm, (2) CustomerTicketMessage.pm, (3) CustomerTicketProcess.pm,…

Patch available
Fix from $1,600 2014-02-04
Infosphere Master Data Management Collaboration Server MEDIUM 6.8
CVE-2013-5427

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 an…

Mitigation only
Fix from $1,600 2014-02-04
Financial Transaction Manager MEDIUM 6.8
CVE-2014-0831

Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote atta…

Mitigation only
Fix from $1,600 2014-02-01
Qradar Security Information And Event Manager MEDIUM 6.8
CVE-2014-0835

Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to hijack the authentication …

Fix: after 7.2.0
Fix from $1,600 2014-01-30
Xibo MEDIUM 6.8
CVE-2013-4889

Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attackers to hijack the authentica…

No fix yet
Fix from $1,600 2014-01-29
Spring Framework MEDIUM 6.8
CVE-2013-6429EPSS 90%

The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolut…

Fix: after 3.2.4
Fix from $1,600 2014-01-26
Cloudforms MEDIUM 6.8
CVE-2013-6443

CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-…

Fix: after 5.2.1
Fix from $1,600 2014-01-23
Blackarmor Nas 220 Firmware MEDIUM 6.8
CVE-2013-6922

Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote atta…

No fix yet
Fix from $1,600 2014-01-21
Moodle MEDIUM 6.8
CVE-2014-0010

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.…

Patch available
Fix from $1,600 2014-01-20
Vcloud Director MEDIUM 6.8
CVE-2014-1211

Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of …

Mitigation only
Fix from $1,600 2014-01-17
Cipcamptiwl 1.0 Firmware MEDIUM 6.8
CVE-2013-7204EPSS 11%

Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attack…

No fix yet
Fix from $1,600 2014-01-17
Netbill MEDIUM 6.8
CVE-2012-6631

Cross-site request forgery (CSRF) vulnerability in accounts/admin/index.php in Vessio NetBill 1.2 allows remote attackers to hijack the authenticatio…

No fix yet
Fix from $1,600 2014-01-16
Newsletter Manager MEDIUM 6.8
CVE-2012-6629

Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allow remote attackers to…

Fix: after 1.0.2
Fix from $1,600 2014-01-16
Vulnerability Manager MEDIUM 6.8
CVE-2014-1473

Multiple cross-site request forgery (CSRF) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow re…

Fix: after 7.5.5
Fix from $1,600 2014-01-16
Icinga MEDIUM 6.8
CVE-2013-7107

Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authenti…

Fix: after 1.10.2
Fix from $1,600 2014-01-15
Atmail MEDIUM 6.8
CVE-2013-6028

Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authentication of…

Fix: after 7.1.6
Fix from $1,600 2014-01-12