Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Tc7200 Firmware MEDIUM 6.8
CVE-2014-0621

Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to hijack the a…

No fix yet
Fix from $1,600 2014-01-08
Firefox Adsense MEDIUM 6.8
CVE-2013-6992

Cross-site request forgery (CSRF) vulnerability in askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin 3.0 and earlier for WordPres…

Fix: after 3.0
Fix from $1,600 2014-01-03
Opsview MEDIUM 6.8
CVE-2013-7256

Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.2 allows remote attackers to hijack the authentication of unspecified victims v…

Fix: after 4.4.1
Fix from $1,600 2014-01-03
Fat Free Crm MEDIUM 6.8
CVE-2013-7223

Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspe…

Fix: after 0.12.0
Fix from $1,600 2014-01-02
Projectforge MEDIUM 6.8
CVE-2013-7251

Multiple cross-site request forgery (CSRF) vulnerabilities in ProjectForge before 5.3 allow remote attackers to hijack the authentication of arbitrar…

Fix: after 5.2
Fix from $1,600 2014-01-02
Jforum MEDIUM 6.8
CVE-2013-7209

Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authenticat…

No fix yet
Fix from $1,600 2013-12-30
Hotbox Router Firmware MEDIUM 5.4
CVE-2013-5039

Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to …

No fix yet
Fix from $1,600 2013-12-30
WordPress MEDIUM 6.8
CVE-2013-7233

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows …

Fix: after 2.0.11
Fix from $1,600 2013-12-30
Enterprise Mrg MEDIUM 6.8
CVE-2013-4405

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers t…

Mitigation only
Fix from $1,600 2013-12-23
Leed MEDIUM 6.8
CVE-2013-2628

Multiple cross-site request forgery (CSRF) vulnerabilities in action.php in Leed (Light Feed), possibly before 1.5 Stable, allow remote attackers to …

Fix: after 1.4
Fix from $1,600 2013-12-21
Epc3925 MEDIUM 6.8
CVE-2013-6976

Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers to hijack the authentication o…

No fix yet
Fix from $1,600 2013-12-19
Ditto Forensic Fieldstation Firmware MEDIUM 6.8
CVE-2013-6883

Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack …

Fix: after 2013oct15a
Fix from $1,600 2013-12-17
Operations Orchestration MEDIUM 6.8
CVE-2013-6192

Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration before 9 allows remote attackers to hijack the authentication of unspe…

Fix: after 7.5
Fix from $1,600 2013-12-17
Webex Training Center MEDIUM 6.8
CVE-2013-6710

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Training Center allows remote attackers to hijack the authentication of unspecified vi…

Mitigation only
Fix from $1,600 2013-12-14
Cognos Command Center MEDIUM 6.8
CVE-2013-4000

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authenticati…

Fix: after 10.1
Fix from $1,600 2013-12-14
Mediawiki MEDIUM 6.8
CVE-2012-5394

Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.2…

Fix: after 1.19.8
Fix from $1,600 2013-12-13
Raidiator MEDIUM 6.8
CVE-2013-2752

Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 al…

Fix: 4.1.12 / 4.2.24+
Fix from $1,600 2013-12-12
Scientific Atlanta Dpr\/epr2320 Firmware HIGH 8.3
CVE-2013-7043

Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote…

No fix yet
Fix from $1,950 2013-12-10
Sharetronix MEDIUM 6.8
CVE-2013-5355

Multiple cross-site request forgery (CSRF) vulnerabilities in Sharetronix 3.1.1 allow remote attackers to hijack the authentication of administrators…

Mitigation only
Fix from $1,600 2013-12-09
2620 24 Poe\+ Switch MEDIUM 6.8
CVE-2013-6852

Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication of adminis…

No fix yet
Fix from $1,600 2013-11-22
Ec Cube MEDIUM 6.8
CVE-2013-5993

Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.0 allows remote attackers to hijack the authentication of arbit…

Patch available
Fix from $1,600 2013-11-21
Document Sciences Xpression MEDIUM 6.8
CVE-2013-6173

Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 b…

No fix yet
Fix from $1,600 2013-11-21
Fortianalyzer Firmware MEDIUM 6.8
CVE-2013-6826

cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which…

Fix: after 5.0.4
Fix from $1,600 2013-11-20
Dsl 2740b Firmware MEDIUM 6.8
CVE-2013-5730

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DSL-2740B Gateway with firmware EU_1.00 allow remote attackers to hijack the aut…

No fix yet
Fix from $1,600 2013-11-20
Dir865l Firmware MEDIUM 6.8
CVE-2013-3095

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to …

Fix: after 1.05
Fix from $1,600 2013-11-20
Blue Wrench Video Widget MEDIUM 6.8
CVE-2013-6797

Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for WordPress allo…

Fix: after 1.0.5
Fix from $1,600 2013-11-19
Blackberry Link MEDIUM 6.8
CVE-2013-3694

BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, whic…

Fix: after 1.2.0.28
Fix from $1,600 2013-11-18
Spip MEDIUM 6.8
CVE-2013-4555

Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP before 2.1.24 allows remote attackers to hijack the authenticatio…

Fix: after 2.1.23
Fix from $1,600 2013-11-18
Tomcat MEDIUM 6.8
CVE-2013-6357

Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the …

Fix: after 5.5.25
Fix from $1,600 2013-11-13
Tweetbot MEDIUM 6.8
CVE-2013-5726

Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attac…

No fix yet
Fix from $1,600 2013-11-12