Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Webnetwork MEDIUM 6.8
CVE-2012-0286

Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspec…

Fix: after 6.0.7.0
Fix from $1,600 2012-01-24
Bugzilla MEDIUM 6.8
CVE-2011-3668

Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the aut…

No fix yet
Fix from $1,600 2012-01-02
Bugzilla MEDIUM 6.8
CVE-2011-3669

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the a…

No fix yet
Fix from $1,600 2012-01-02
Xt Commerce MEDIUM 6.8
CVE-2011-5011

Multiple cross-site request forgery (CSRF) vulnerabilities in xt:Commerce 3.0.4 SP2.1 and possibly earlier allow remote attackers to hijack the authe…

Mitigation only
Fix from $1,600 2011-12-25
Wuzly MEDIUM 6.8
CVE-2011-3836

Multiple cross-site request forgery (CSRF) vulnerabilities in Wuzly 2.0 allow remote attackers to hijack the authentication of administrators for req…

Mitigation only
Fix from $1,600 2011-12-24
Homeseer Hs2 MEDIUM 6.8
CVE-2011-4837

Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authenti…

Mitigation only
Fix from $1,600 2011-12-15
Freeipa MEDIUM 6.8
CVE-2011-3636

Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authenticat…

Fix: after 2.1.3
Fix from $1,600 2011-12-08
Zenprise Device Manager MEDIUM 6.8
CVE-2011-4498

Cross-site request forgery (CSRF) vulnerability in the web console in Zenprise Device Manager 6.x through 6.1.8 allows remote attackers to hijack the…

Patch available
Fix from $1,600 2011-11-21
Mahara MEDIUM 6.8
CVE-2011-2773

Cross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1 allows remote attackers to hijack the authentication of administrators for req…

Fix: after 1.4.0
Fix from $1,600 2011-11-15
Autotagging MEDIUM 6.8
CVE-2011-3994

Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earl…

Fix: after 5.251
Fix from $1,600 2011-11-03
Small Business Srp521w HIGH 9.3
CVE-2011-4005

Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521…

Fix: after 1.02.01_mr2
Fix from $1,950 2011-11-03
App Engine Python Sdk MEDIUM 6.8
CVE-2011-1364

Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console)…

Fix: after 1.5.3
Fix from $1,600 2011-10-30
Smf MEDIUM 6.8
CVE-2011-4173

Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authentication …

Mitigation only
Fix from $1,600 2011-10-24
Django MEDIUM 6.8
CVE-2011-4140

The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary…

Fix: after 1.2.6
Fix from $1,600 2011-10-19
Apphp Calendar MEDIUM 6.8
CVE-2010-4881

Multiple cross-site request forgery (CSRF) vulnerabilities in calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote attackers to hijack the a…

No fix yet
Fix from $1,600 2011-10-07
Cherokee MEDIUM 6.8
CVE-2011-2191

Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of a…

Fix: after 1.2.98
Fix from $1,600 2011-10-07
Jasperreports Server Community Project MEDIUM 6.8
CVE-2011-1911

JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remo…

Mitigation only
Fix from $1,600 2011-09-20
Phorum MEDIUM 6.8
CVE-2011-3381

Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified victims v…

Fix: after 5.2.15
Fix from $1,600 2011-09-08
Aipo MEDIUM 6.8
CVE-2011-1341

Cross-site request forgery (CSRF) vulnerability in Aimluck Aipo before 4.0.4.0, and Aipo for ASP before 4.0.4.0, allows remote attackers to hijack th…

Fix: after 4.0.3.0
Fix from $1,600 2011-08-19
Endpoint Protection MEDIUM 6.8
CVE-2011-0551

Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.60…

Mitigation only
Fix from $1,600 2011-08-15
Debian Linux MEDIUM 6.8
CVE-2011-2522EPSS 10%

Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attack…

Fix: 3.3.16 / 3.4.14+
Fix from $1,600 2011-07-29
Network Satellite Server MEDIUM 6.8
CVE-2009-4139

A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authent…

Patch available
Fix from $1,600 2011-07-27
Websphere Application Server MEDIUM 6.8
CVE-2010-3271

Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Applicat…

Fix: after 7.0.0.13
Fix from $1,600 2011-07-18
Squirrelmail MEDIUM 6.8
CVE-2011-2753

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of …

Fix: after 1.4.21
Fix from $1,600 2011-07-17
Php Nuke MEDIUM 6.8
CVE-2011-1482

Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hija…

Fix: after 8.0
Fix from $1,600 2011-06-21
Coldfusion MEDIUM 6.8
CVE-2011-0629

Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to hijack the authentication o…

Patch available
Fix from $1,600 2011-06-16
Post Revolution MEDIUM 6.8
CVE-2011-1954

Multiple cross-site request forgery (CSRF) vulnerabilities in Post Revolution 0.8.0c-2 and earlier allow remote attackers to hijack the authenticatio…

Fix: after 0.8.0c-2
Fix from $1,600 2011-06-06
Archiva MEDIUM 6.8
CVE-2011-1026

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hij…

No fix yet
Fix from $1,600 2011-06-02
Mahara MEDIUM 6.8
CVE-2011-1403

Cross-site request forgery (CSRF) vulnerability in the pieforms implementation in Mahara before 1.3.6 allows remote attackers to hijack the authentic…

Fix: after 1.3.5
Fix from $1,600 2011-05-13
Ec Cube MEDIUM 5.8
CVE-2011-1325

Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims …

Fix: after 2.11.0
Fix from $1,600 2011-05-13