Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Bbr 4hg Firmware MEDIUM 5.8
CVE-2011-1324

Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmw…

Mitigation only
Fix from $1,600 2011-05-09
Messaging Security Gateway MEDIUM 6.8
CVE-2011-1905

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified administrative modules in Proofpoint Messaging Security Gateway 6.2.0.263:6…

Fix: after 6.2.0.263
Fix from $1,600 2011-05-05
Insight Control Performance Management MEDIUM 6.8
CVE-2011-1545

Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.3 allows remote attackers to hijack the authent…

Fix: after 6.2
Fix from $1,600 2011-05-03
Phplist MEDIUM 6.8
CVE-2011-0748

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administr…

Fix: after 2.10.12
Fix from $1,600 2011-04-13
Translation Management MEDIUM 6.8
CVE-2011-1664

Cross-site request forgery (CSRF) vulnerability in the Translation Management module 6.x before 6.x-1.21 for Drupal allows remote attackers to hijack…

Patch available
Fix from $1,600 2011-04-10
Mahara MEDIUM 5.8
CVE-2011-0440

Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authenticat…

Mitigation only
Fix from $1,600 2011-03-28
Liveupdate Administrator MEDIUM 6.8
CVE-2011-0545

Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack…

No fix yet
Fix from $1,600 2011-03-28
Wp Recaptcha MEDIUM 6.8
CVE-2011-0759

Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration page in the Recaptcha (aka WP-reCAPTCHA) plugin 2.9.8.2 for WordPress…

Mitigation only
Fix from $1,600 2011-03-22
Firefox MEDIUM 6.8
CVE-2011-0059

Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote …

Fix: after 2.0.11
Fix from $1,600 2011-03-02
Blog\ MEDIUM 6.8
CVE-2010-4750

Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack …

Patch available
Fix from $1,600 2011-03-01
Evm MEDIUM 6.8
CVE-2011-1104

Multiple cross-site request forgery (CSRF) vulnerabilities in Mutare EVM allow remote attackers to hijack the authentication of arbitrary users for r…

Mitigation only
Fix from $1,600 2011-02-28
Rails MEDIUM 6.8
CVE-2011-0447

Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With …

Patch available
Fix from $1,600 2011-02-14
Django MEDIUM 6.8
CVE-2011-0696

Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly validate HTTP requests that contain an X-Requested-With header, which makes it eas…

Patch available
Fix from $1,600 2011-02-14
Power Manager MEDIUM 6.8
CVE-2011-0277

Cross-site request forgery (CSRF) vulnerability in HP Power Manager (HPPM) 4.3.2 and earlier allows remote attackers to hijack the authentication of …

Fix: after 4.3.2
Fix from $1,600 2011-02-09
Smcd3g Ccr MEDIUM 6.8
CVE-2011-0886

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware be…

Fix: after 1.4.0.49
Fix from $1,600 2011-02-08
Zikula Application Framework MEDIUM 6.8
CVE-2011-0535

Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of ad…

Fix: after 1.2.4
Fix from $1,600 2011-02-08
Zikula Application Framework MEDIUM 6.8
CVE-2010-4729

Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier f…

Fix: after 1.2.2
Fix from $1,600 2011-02-08
Greenbone Security Assistant MEDIUM 6.8
CVE-2011-0650

Cross-site request forgery (CSRF) vulnerability in Greenbone Security Assistant (GSA) before 2.0+rc3 allows remote attackers to hijack the authentica…

Fix: after 2.0
Fix from $1,600 2011-01-28
Bugzilla MEDIUM 6.8
CVE-2011-0046

Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc…

Fix: after 3.2.9
Fix from $1,600 2011-01-28
Php Link Directory MEDIUM 6.8
CVE-2011-0643

Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack th…

No fix yet
Fix from $1,600 2011-01-25
Vam Shop MEDIUM 6.8
CVE-2011-0503

Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote attackers to hijack the authentic…

Fix: after 1.6.1
Fix from $1,600 2011-01-20
Mybb MEDIUM 6.8
CVE-2010-4627

Cross-site request forgery (CSRF) vulnerability in usercp2.php in MyBB (aka MyBulletinBoard) before 1.4.12 allows remote attackers to hijack the auth…

Fix: after 1.4.11
Fix from $1,600 2010-12-30
Ispot Firmware HIGH 9.3
CVE-2010-4507

Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmware 1.9.9…

No fix yet
Fix from $1,950 2010-12-30
Views MEDIUM 6.8
CVE-2010-4519

Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2…

Patch available
Fix from $1,600 2010-12-23
Archiva MEDIUM 6.8
CVE-2010-3449

Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through …

Fix: after 1.2.3
Fix from $1,600 2010-12-06
Omnifind MEDIUM 6.8
CVE-2010-3891

Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 a…

Fix: after 9.0
Fix from $1,600 2010-11-12
Horde Application Framework MEDIUM 6.8
CVE-2010-3694

Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework before 3.3.9 allows remote attackers to hijack the authentication …

Fix: after 3.3.8
Fix from $1,600 2010-11-09
Websphere Application Server MEDIUM 6.0
CVE-2010-0785

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 b…

Mitigation only
Fix from $1,600 2010-11-09
Insight Control For Linux MEDIUM 6.8
CVE-2010-4106

Cross-site request forgery (CSRF) vulnerability in HP Insight Control for Linux before 6.2 allows remote attackers to hijack the authentication of un…

Fix: after 6.1
Fix from $1,600 2010-11-02
Insight Control Performance Management MEDIUM 6.8
CVE-2010-4032

Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to hijack the authent…

Fix: after 6.1
Fix from $1,600 2010-11-02