Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Tririga Application Platform MEDIUM 6.8
CVE-2012-5950

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers …

Mitigation only
Fix from $1,600 2013-04-23
Wp Downloadmanager MEDIUM 6.8
CVE-2013-2697

Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the auth…

Fix: after 1.60
Fix from $1,600 2013-04-19
Jboss Enterprise Portal Platform MEDIUM 6.8
CVE-2012-3532

Cross-site request forgery (CSRF) vulnerability in the GateIn Portal component in JBoss Enterprise Portal Platform 5.2.2 and earlier allows remote at…

Fix: after 5.2.2
Fix from $1,600 2013-04-12
Omniauth Oauth2 MEDIUM 6.8
CVE-2012-6134

Cross-site request forgery (CSRF) vulnerability in the omniauth-oauth2 gem 1.1.1 and earlier for Ruby allows remote attackers to hijack the authentic…

Fix: 1.1.1+
Fix from $1,600 2013-04-09
Php Address Book HIGH 7.5
CVE-2013-2778

Cross-site request forgery (CSRF) vulnerability in addressbook/register/delete_user.php in PHP Address Book 8.2.5 allows remote attackers to hijack t…

Mitigation only
Fix from $1,950 2013-04-09
Magelis Xbt Hmi HIGH 10.0
CVE-2013-2762

The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remot…

Mitigation only
Fix from $1,950 2013-04-04
Modicon Quantum Plc MEDIUM 6.8
CVE-2013-0663EPSS 6%

Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0…

No fix yet
Fix from $1,600 2013-04-04
Security Appscan MEDIUM 6.8
CVE-2013-0532

Cross-site request forgery (CSRF) vulnerability in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x …

Mitigation only
Fix from $1,600 2013-03-29
Software Use Analysis MEDIUM 6.8
CVE-2013-0452

Cross-site request forgery (CSRF) vulnerability in the Software Use Analysis (SUA) application before 1.3.3 in IBM Tivoli Endpoint Manager 8.2 allows…

Fix: after 1.3.2
Fix from $1,600 2013-03-29
Procurve Switch Software MEDIUM 6.8
CVE-2012-5216

Cross-site request forgery (CSRF) vulnerability on HP ProCurve 1700-8 (aka J9079A) switches with software before VA.02.09 and 1700-24 (aka J9080A) sw…

Mitigation only
Fix from $1,600 2013-03-28
Taxonomy Manager MEDIUM 5.1
CVE-2013-0320

Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-r…

Patch available
Fix from $1,600 2013-03-27
Lotus Domino MEDIUM 6.0
CVE-2013-0489

Cross-site request forgery (CSRF) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote authenticated us…

Mitigation only
Fix from $1,600 2013-03-27
Fios Actiontec Mi424wr Gen31 Router Firmware MEDIUM 6.8
CVE-2013-0126

Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 all…

No fix yet
Fix from $1,600 2013-03-21
Atermwm3450rn MEDIUM 6.8
CVE-2013-0717

Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, A…

Mitigation only
Fix from $1,600 2013-03-19
Mark Complete MEDIUM 6.8
CVE-2013-0207

Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the a…

Mitigation only
Fix from $1,600 2013-03-19
Jenkins MEDIUM 6.8
CVE-2013-0327

Cross-site request forgery (CSRF) vulnerability in Jenkins master in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to hijack th…

Fix: after 1.501
Fix from $1,600 2013-03-19
Restful Web Services MEDIUM 6.8
CVE-2013-0205

Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 …

Fix: 7.x-1.2+
Fix from $1,600 2013-03-19
Piwigo HIGH 7.6
CVE-2013-1468EPSS 6%

Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authenti…

Fix: after 2.4.6
Fix from $1,950 2013-03-14
Prime Infrastructure MEDIUM 6.8
CVE-2013-1153

Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authenticati…

Mitigation only
Fix from $1,600 2013-03-07
Netezza MEDIUM 6.8
CVE-2012-5763

Cross-site request forgery (CSRF) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote attackers to…

Mitigation only
Fix from $1,600 2013-02-20
Unified Meetingplace MEDIUM 6.8
CVE-2013-1128

Multiple cross-site request forgery (CSRF) vulnerabilities in the server in Cisco Unified MeetingPlace before 7.1(2.2000) allow remote attackers to h…

Fix: after 7.1
Fix from $1,600 2013-02-15
Opera Browser MEDIUM 6.8
CVE-2013-1639

Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism v…

Fix: after 12.12
Fix from $1,600 2013-02-08
Unity Express Software MEDIUM 6.8
CVE-2013-1120

Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the a…

Fix: after 7.4
Fix from $1,600 2013-02-06
Samba MEDIUM 5.1
CVE-2013-0214

Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x …

Mitigation only
Fix from $1,600 2013-02-02
Moodle MEDIUM 6.8
CVE-2012-6103

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x befo…

Mitigation only
Fix from $1,600 2013-01-27
Websphere Application Server MEDIUM 6.8
CVE-2013-0460

Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 …

Mitigation only
Fix from $1,600 2013-01-27
Diy Cms MEDIUM 6.8
CVE-2012-6518

Cross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authentication of administrators for …

No fix yet
Fix from $1,600 2013-01-24
Car Portal MEDIUM 6.8
CVE-2012-6508

Multiple cross-site request forgery (CSRF) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to hijack the authentication of admi…

No fix yet
Fix from $1,600 2013-01-24
Wlm 2501 MEDIUM 6.8
CVE-2012-1922

Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the authentication of administrators …

Mitigation only
Fix from $1,600 2013-01-24
Webex Training Center MEDIUM 6.8
CVE-2013-1109

Cross-site request forgery (CSRF) vulnerability in testingLibraryAction.do in the Training Center testing library in Cisco WebEx Training Center allo…

Mitigation only
Fix from $1,600 2013-01-17