Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Lotus Domino MEDIUM 6.0
CVE-2013-4050

Cross-site request forgery (CSRF) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated use…

Mitigation only
Fix from $1,600 2013-11-08
Zenworks Configuration Management MEDIUM 6.8
CVE-2013-6346

Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attacke…

Fix: after 11.2.3
Fix from $1,600 2013-11-02
Social Sharing Toolkit Plugin MEDIUM 6.8
CVE-2013-2701

Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authen…

Mitigation only
Fix from $1,600 2013-11-01
Cart66 Lite Plugin MEDIUM 6.8
CVE-2013-5977

Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers …

Fix: after 1.5.1.14
Fix from $1,600 2013-11-01
Drupal MEDIUM 6.8
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hij…

Mitigation only
Fix from $1,600 2013-10-28
Taxweb MEDIUM 6.8
CVE-2013-6018

Cross-site request forgery (CSRF) vulnerability in login.jsp in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to hijack the authenticati…

Mitigation only
Fix from $1,600 2013-10-28
Bugzilla MEDIUM 6.8
CVE-2013-1734

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.…

Patch available
Fix from $1,600 2013-10-24
Bugzilla MEDIUM 6.8
CVE-2013-1733

Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authenticatio…

Patch available
Fix from $1,600 2013-10-24
Junos MEDIUM 5.1
CVE-2013-4689

J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 1…

Fix: after 10.4
Fix from $1,600 2013-10-17
Infosphere Information Server MEDIUM 6.8
CVE-2013-4056

Cross-site request forgery (CSRF) vulnerability in the Data Quality Console and Information Analyzer components in IBM InfoSphere Information Server …

Mitigation only
Fix from $1,600 2013-10-13
Mediawiki MEDIUM 6.8
CVE-2013-4306

Cross-site request forgery (CSRF) vulnerability in api/ApiQueryCheckUser.php in the CheckUser extension for MediaWiki, possibly Checkuser before 2.3,…

Fix: 1.19.8 / 1.20.7+
Fix from $1,600 2013-10-11
Mingle Forum MEDIUM 6.8
CVE-2013-0736

Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for WordPress allow remote attacker…

Fix: after 1.0.34
Fix from $1,600 2013-10-09
Unified Computing System MEDIUM 6.8
CVE-2012-4084

Cross-site request forgery (CSRF) vulnerability in the web-management interface in the fabric interconnect (FI) component in Cisco Unified Computing …

Mitigation only
Fix from $1,600 2013-10-05
Airlive Od 2025hd MEDIUM 6.8
CVE-2013-3540

Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/usrgrp.cgi in AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD,…

No fix yet
Fix from $1,600 2013-10-04
100ap Device Firmware MEDIUM 6.8
CVE-2013-3690EPSS 12%

Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and po…

Mitigation only
Fix from $1,600 2013-10-01
Gxv Device Firmware MEDIUM 6.8
CVE-2013-3963

Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P…

Fix: after 1.0.4.43
Fix from $1,600 2013-10-01
Airlive Wl2600cam MEDIUM 6.8
CVE-2013-3539EPSS 9%

Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SN…

No fix yet
Fix from $1,600 2013-10-01
Rational Clearquest MEDIUM 6.8
CVE-2013-0598

Cross-site request forgery (CSRF) vulnerability in the Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 befor…

Mitigation only
Fix from $1,600 2013-09-28
Click2sell Suite Module MEDIUM 6.8
CVE-2013-5937

Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authenticatio…

Mitigation only
Fix from $1,600 2013-09-25
Glpi MEDIUM 6.8
CVE-2013-5696EPSS 8%

inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows…

Fix: after 0.84.1
Fix from $1,600 2013-09-23
Unified Meetingplace MEDIUM 6.8
CVE-2013-5494

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Unified MeetingPlace Solution, as used in Unified MeetingPlace Web Conf…

Mitigation only
Fix from $1,600 2013-09-16
Testimonial Plugin MEDIUM 6.8
CVE-2013-5672

Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow remote attackers to hijack the …

No fix yet
Fix from $1,600 2013-09-10
Coursemill Learning Management System MEDIUM 6.8
CVE-2013-5708

Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct …

No fix yet
Fix from $1,600 2013-09-06
Coursemill Learning Management System MEDIUM 6.8
CVE-2013-3605

Cross-site request forgery (CSRF) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to hijack the authenticati…

Mitigation only
Fix from $1,600 2013-09-06
Global Site Selector MEDIUM 6.8
CVE-2013-5471

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Global Site Selector (GSS) allows remote attackers to hijack the authen…

Mitigation only
Fix from $1,600 2013-09-05
Sharethis MEDIUM 6.8
CVE-2013-3479

Cross-site request forgery (CSRF) vulnerability in the ShareThis plugin before 7.0.6 for WordPress allows remote attackers to hijack the authenticati…

Fix: after 7.0.5
Fix from $1,600 2013-09-05
Unified Communications Manager MEDIUM 6.8
CVE-2013-3472

Cross-site request forgery (CSRF) vulnerability in the Enterprise License Manager (ELM) in Cisco Unified Communications Manager (CM) allows remote at…

Mitigation only
Fix from $1,600 2013-08-29
Epm Suite MEDIUM 6.8
CVE-2013-3583

Cross-site request forgery (CSRF) vulnerability in saveProperties.html in Corporater EPM Suite allows remote attackers to hijack the authentication o…

Mitigation only
Fix from $1,600 2013-08-28
Websphere Application Server MEDIUM 6.8
CVE-2013-3029

Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 befo…

Mitigation only
Fix from $1,600 2013-08-21
Ritecms MEDIUM 6.8
CVE-2013-5316

Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests …

No fix yet
Fix from $1,600 2013-08-20