Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
E107 MEDIUM 6.8
CVE-2012-6433

Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of admi…

Patch available
Fix from $1,600 2013-01-03
E107 MEDIUM 6.8
CVE-2012-6434

Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attackers to hijack the authenticati…

Patch available
Fix from $1,600 2013-01-03
Wireless Lan Controller Software MEDIUM 6.8
CVE-2012-5992

Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attack…

No fix yet
Fix from $1,600 2012-12-19
Welcart Plugin MEDIUM 6.8
CVE-2012-5178

Cross-site request forgery (CSRF) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to hijack the authentication…

Fix: after 1.2.1
Fix from $1,600 2012-12-19
Openshift MEDIUM 6.8
CVE-2012-5622

Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift …

Patch available
Fix from $1,600 2012-12-18
Rsa Netwitness Informer MEDIUM 6.8
CVE-2012-4608

Cross-site request forgery (CSRF) vulnerability in the web interface in EMC RSA NetWitness Informer before 2.0.5.6 allows remote attackers to hijack …

Fix: after 2.0.5.5
Fix from $1,600 2012-12-05
Commerce Extra Panes MEDIUM 6.8
CVE-2012-5542

Cross-site request forgery (CSRF) vulnerability in the Commerce Extra Panes module 7.x-1.x before 7.x-1.1 in Drupal allows remote attackers to hijack…

Patch available
Fix from $1,600 2012-12-03
Search Api MEDIUM 6.8
CVE-2012-5547

Multiple cross-site request forgery (CSRF) vulnerabilities in the Search API module 7.x-1.x before 7.x-1.3 for Drupal allow remote attackers to hijac…

Patch available
Fix from $1,600 2012-12-03
Time Spent MEDIUM 6.8
CVE-2012-5549

Cross-site request forgery (CSRF) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to hijack the authentication …

Mitigation only
Fix from $1,600 2012-12-03
Restful Web Services MEDIUM 6.8
CVE-2012-5556

Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.1 and 7.x-2.x before 7.x-…

Patch available
Fix from $1,600 2012-12-03
Cms Made Simple MEDIUM 6.8
CVE-2012-5450

Cross-site request forgery (CSRF) vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) 1.11.2 and earlier allows remot…

Fix: after 1.11.2
Fix from $1,600 2012-12-03
Drag \& Drop Gallery MEDIUM 6.8
CVE-2012-4478

Cross-site request forgery (CSRF) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to hijack the authentication…

Patch available
Fix from $1,600 2012-11-30
X7 Chat MEDIUM 6.8
CVE-2012-6047

Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the authentication of administrators…

Fix: after 2.0.5.1
Fix from $1,600 2012-11-27
Livelink Ecm MEDIUM 6.8
CVE-2010-5283

Cross-site request forgery (CSRF) vulnerability in OpenText ECM (formerly Livelink ECM) 9.7.1 allows remote attackers to hijack the authentication of…

No fix yet
Fix from $1,600 2012-11-26
Collabtive MEDIUM 6.8
CVE-2010-5285

Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrato…

No fix yet
Fix from $1,600 2012-11-26
Jboss Enterprise Brms Platform MEDIUM 6.0
CVE-2011-2908

Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.…

Fix: after 5.2.1
Fix from $1,600 2012-11-23
Firefox MEDIUM 6.8
CVE-2012-4205

Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XM…

Fix: 2.14 / 17.0+
Fix from $1,600 2012-11-21
Fleetcommander MEDIUM 6.8
CVE-2012-4943

Multiple cross-site request forgery (CSRF) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to hij…

Fix: after 4.0
Fix from $1,600 2012-11-18
Pattern Insight MEDIUM 6.8
CVE-2012-4935

Cross-site request forgery (CSRF) vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack the authentication of a…

Mitigation only
Fix from $1,600 2012-11-18
Landshop MEDIUM 6.8
CVE-2012-5898

Cross-site request forgery (CSRF) vulnerability in SAMEDIA LandShop 0.9.2 allows remote attackers to hijack the authentication of administrators for …

No fix yet
Fix from $1,600 2012-11-17
Dalbum MEDIUM 6.8
CVE-2012-5891

Multiple cross-site request forgery (CSRF) vulnerabilities in photo/pass.php in DAlbum 1.44 build 174 and earlier allow remote attackers to hijack th…

Fix: after 1.44
Fix from $1,600 2012-11-17
Websphere Application Server MEDIUM 6.8
CVE-2012-4853

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and…

Mitigation only
Fix from $1,600 2012-11-14
Rt MEDIUM 6.8
CVE-2012-4732

Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before …

Patch available
Fix from $1,600 2012-11-11
Subuser MEDIUM 6.8
CVE-2012-4486

Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers to hijack the authentication …

Fix: after 6.x-1.7
Fix from $1,600 2012-11-02
Sentinel MEDIUM 6.8
CVE-2011-5226

Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijac…

Mitigation only
Fix from $1,600 2012-10-25
White Label Cms MEDIUM 6.8
CVE-2012-5387

Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers …

Fix: after 1.5
Fix from $1,600 2012-10-24
Subrion Cms MEDIUM 6.8
CVE-2012-4773

Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of adminis…

Fix: after 2.2.2
Fix from $1,600 2012-10-22
Razorcms MEDIUM 6.8
CVE-2012-1900

Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication…

Fix: after 1.2.1
Fix from $1,600 2012-10-22
Glpi MEDIUM 6.8
CVE-2012-4002

Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentication of unspecifie…

Fix: after 0.83.2
Fix from $1,600 2012-10-09
Isupport MEDIUM 6.8
CVE-2012-5326

Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers to hijack the authentication o…

No fix yet
Fix from $1,600 2012-10-08