Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2017-1631 IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute ma… Jazz For Service Management Patch available Fix from $1,9502017-12-20 HIGH 8.8 CVE-2017-1746 IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute ma… Jazz For Service Management Patch available Fix from $1,9502017-12-20 HIGH 8.8 CVE-2017-17774 admin/configuration.php in Piwigo 2.9.2 has CSRF. Piwigo Patch available Fix from $1,9502017-12-20 HIGH 8.8 CVE-2017-14092 The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated request… Scanmail Patch available Fix from $1,9502017-12-16 HIGH 8.8 CVE-2017-5264 Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web app… Nexpose 6.4.66+ Fix from $1,9502017-12-14 HIGH 7.3 CVE-2017-14362 Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited … Project And Portfolio Management Mitigation only Fix from $1,9502017-12-13 HIGH 8.8 CVE-2017-17056 The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function o… Zktime Web No fix yet Fix from $1,9502017-12-04 HIGH 8.8 CVE-2017-12631 Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty… Cxf Fediz 1.3.3+ Fix from $1,9502017-11-30 HIGH 8.8 CVE-2016-10701 In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application. Pentaho Business Analytics after 8.0 Fix from $1,9502017-11-28 HIGH 8.8 CVE-2017-8138 HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a websit… Hedex Lite Mitigation only Fix from $1,9502017-11-22 HIGH 7.5 CVE-2017-4928 The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRL… Vcenter Server Patch available Fix from $1,9502017-11-17 MEDIUM 6.5 CVE-2017-1000224 CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin Youtube after 11.8.1 Fix from $1,6002017-11-17 HIGH 8.8 CVE-2017-15516 NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause a… Snapcenter Server Patch available Fix from $1,9502017-11-16 HIGH 8.8 CVE-2017-7851 D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a subst… Dcs 936l 1.05.07+ Fix from $1,9502017-11-15 HIGH 8.8 CVE-2017-11876 Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are no… Project Server Patch available Fix from $1,9502017-11-15 CRITICAL 9.8 CVE-2017-16780EPSS 6% The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file. Mybb after 1.8.12 Fix from $2,3002017-11-10 HIGH 8.0 CVE-2017-16563 Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to … Ht802 Firmware No fix yet Fix from $1,9502017-11-06 HIGH 8.8 CVE-2017-16565 Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login scree… Ht802 Firmware No fix yet Fix from $1,9502017-11-06 HIGH 8.8 CVE-2017-16570 KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_… Keystone 4.0.0+ Fix from $1,9502017-11-06 MEDIUM 6.8 CVE-2017-1000147 Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the u… Mahara Patch available Fix from $1,6002017-11-03 HIGH 8.8 CVE-2017-1300 IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut… Openpages Grc Platform Patch available Fix from $1,9502017-11-01 HIGH 8.8 CVE-2017-1000244 Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification Favorite after 2.2.0 Fix from $1,9502017-11-01 HIGH 8.8 CVE-2017-16244 Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an … October Patch available Fix from $1,9502017-11-01 HIGH 8.8 CVE-2015-5170 Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to… Cf Release 1.7.0 / 2.5.2+ Fix from $1,9502017-10-24 HIGH 8.8 CVE-2012-4568 Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to hijack the authenticati… Letodms after 3.3.7 Fix from $1,9502017-10-23 HIGH 8.8 CVE-2015-2878 Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of admin… Hawkeye G No fix yet Fix from $1,9502017-10-23 HIGH 8.8 CVE-2017-15808 In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php. Phpmyfaq after 2.9.8 Fix from $1,9502017-10-23 HIGH 8.8 CVE-2017-15729 In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary. Phpmyfaq after 2.9.8 Fix from $1,9502017-10-22 HIGH 8.8 CVE-2017-15730 In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php. Phpmyfaq after 2.9.8 Fix from $1,9502017-10-22 HIGH 8.8 CVE-2017-15731 In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php. Phpmyfaq after 2.9.8 Fix from $1,9502017-10-22