Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Free Realty MEDIUM 6.8
CVE-2012-4280

Multiple cross-site request forgery (CSRF) vulnerabilities in admin/agenteditor.php in Free Realty 3.1-0.6 allow remote attackers to hijack the authe…

No fix yet
Fix from $1,600 2012-08-13
Mysqldumper MEDIUM 5.1
CVE-2012-4252

Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrator…

No fix yet
Fix from $1,600 2012-08-13
Orion Network Performance Monitor MEDIUM 6.8
CVE-2012-2602EPSS 6%

Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers…

Fix: after 10.2.2
Fix from $1,600 2012-08-12
Socketmail MEDIUM 6.8
CVE-2012-4059

Cross-site request forgery (CSRF) vulnerability in home/secretqtn.php in SocketMail Pro 2.2.9 allows remote attackers to hijack the authentication of…

No fix yet
Fix from $1,600 2012-07-25
Addressbook MEDIUM 6.8
CVE-2012-2307

Cross-site request forgery (CSRF) vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to hijack the authen…

Fix: after 6.x-4.2
Fix from $1,600 2012-07-25
Node Gallery MEDIUM 6.8
CVE-2012-2305

Cross-site request forgery (CSRF) vulnerability in the Node Gallery module for Drupal 6.x-3.1 and earlier allows remote attackers to hijack the authe…

Fix: after 6.x-3.1
Fix from $1,600 2012-07-25
Ez Publish MEDIUM 6.8
CVE-2012-4053

Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the authenticati…

Mitigation only
Fix from $1,600 2012-07-25
WordPress MEDIUM 6.8
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of u…

Fix: after 3.4.0
Fix from $1,600 2012-07-22
Moodle MEDIUM 6.8
CVE-2011-4133

Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified vic…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.8
CVE-2011-4281

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitr…

Mitigation only
Fix from $1,600 2012-07-16
Extplorer MEDIUM 6.8
CVE-2012-3362

Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrato…

Fix: after 2.1.0
Fix from $1,600 2012-07-12
Moodle MEDIUM 6.8
CVE-2011-4298

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote a…

Patch available
Fix from $1,600 2012-07-11
Netsweeper MEDIUM 6.8
CVE-2012-2447

Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote attackers to hijack …

No fix yet
Fix from $1,600 2012-07-09
Message Filter MEDIUM 6.8
CVE-2012-0303

Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hija…

Fix: after 6.3
Fix from $1,600 2012-07-05
Web\@all MEDIUM 6.8
CVE-2012-3231

Multiple cross-site request forgery (CSRF) vulnerabilities in web@all 2.0, as downloaded before May 30, 2012, allow remote attackers to hijack the au…

No fix yet
Fix from $1,600 2012-06-27
Maestro MEDIUM 5.1
CVE-2012-3799

Multiple cross-site request forgery (CSRF) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote attackers to hijack t…

Patch available
Fix from $1,600 2012-06-27
Node Hierarchy MEDIUM 6.8
CVE-2012-2728

Multiple cross-site request forgery (CSRF) vulnerabilities in the Node Hierarchy module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to h…

Patch available
Fix from $1,600 2012-06-27
Simplemeta MEDIUM 6.8
CVE-2012-2729

Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleMeta module 6.x-1.x before 6.x-2.0 for Drupal allow remote attackers to hijac…

Patch available
Fix from $1,600 2012-06-27
Browserid MEDIUM 6.8
CVE-2012-2713

Cross-site request forgery (CSRF) vulnerability in the BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers t…

Patch available
Fix from $1,600 2012-06-27
Roller MEDIUM 6.8
CVE-2012-2380

Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack…

Fix: after 5.0
Fix from $1,600 2012-06-26
Comment Moderation MEDIUM 6.8
CVE-2012-2716

Cross-site request forgery (CSRF) vulnerability in the Comment Moderation module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to hijack …

Patch available
Fix from $1,600 2012-06-21
Network Sentry Appliance Software MEDIUM 6.8
CVE-2012-2605

Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bradford Network Sentry before 5.3.3 allow remote attac…

Fix: after 5.3
Fix from $1,600 2012-06-13
Identity Management Suite MEDIUM 5.1
CVE-2012-2959

Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote atta…

No fix yet
Fix from $1,600 2012-06-11
Web Filtering MEDIUM 6.8
CVE-2012-2564

Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bloxx Web Filtering before 5.0.14 allow remote attacker…

Fix: after 5.0.13
Fix from $1,600 2012-06-09
Web Filtering MEDIUM 6.8
CVE-2012-3343

Cross-site request forgery (CSRF) vulnerability in Microdasys before 3.5.1-B708, as used in Bloxx Web Filtering before 5.0.14 and other products, all…

Fix: after 5.0.13
Fix from $1,600 2012-06-09
Rt MEDIUM 6.8
CVE-2011-2085

Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote attackers t…

Fix: after 3.8.11
Fix from $1,600 2012-06-04
Take Control MEDIUM 6.8
CVE-2012-2341

Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the au…

Mitigation only
Fix from $1,600 2012-05-18
WordPress MEDIUM 6.8
CVE-2012-1936

The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a user ses…

Fix: after 3.3.1
Fix from $1,600 2012-05-03
Rational Appscan MEDIUM 6.0
CVE-2012-0730

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allow remote attackers to hi…

Mitigation only
Fix from $1,600 2012-05-03
Insight Management Agents MEDIUM 6.8
CVE-2012-2003

Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attacker…

Fix: after 8.70.0.0
Fix from $1,600 2012-05-02