Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2017-7557 dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack. Dnsdist Patch available Fix from $1,9502017-08-22 HIGH 8.8 CVE-2017-5187 A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Deve… Directory Server after 2.3 Fix from $1,9502017-08-21 HIGH 8.8 CVE-2017-7423 A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 befor… Enterprise Developer Mitigation only Fix from $1,9502017-08-21 HIGH 8.8 CVE-2017-12881 Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin before 1.3.0 allows remote attackers to hijack the authentication of unspec… Spring Batch Admin after 1.2.1 Fix from $1,9502017-08-18 HIGH 8.8 CVE-2015-5081 Cross-site request forgery (CSRF) vulnerability in django CMS before 3.0.14, 3.1.x before 3.1.1 allows remote attackers to manipulate privileged user… Django Cms after 3.0.13 Fix from $1,9502017-08-18 HIGH 8.8 CVE-2017-12589 ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack. R60g Firmware No fix yet Fix from $1,9502017-08-18 HIGH 8.8 CVE-2017-12593 ASUS DSL-N10S V2.1.16_APAC devices allow CSRF. Dsl N10s Firmware No fix yet Fix from $1,9502017-08-18 HIGH 8.8 CVE-2017-7556 Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website con… Hawtio Mitigation only Fix from $1,9502017-08-17 HIGH 8.8 CVE-2017-12853 The RealTime RWR-3G-100 Router Firmware Version : Ver1.0.56 is affected by CSRF an attack that forces an end user to execute unwanted actions on a we… Rwr 3g 100 Firmware No fix yet Fix from $1,9502017-08-14 HIGH 8.8 CVE-2017-6328 The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbrevia… Message Gateway after 10.6.3-2 Fix from $1,9502017-08-11 HIGH 8.8 CVE-2017-12651 Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress beca… Loginizer after 1.3.5 Fix from $1,9502017-08-07 HIGH 8.8 CVE-2017-6756 A vulnerability in the Web UI Application of the Cisco Prime Collaboration Provisioning Tool through 12.2 could allow an unauthenticated, remote atta… Prime Collaboration Provisioning Mitigation only Fix from $1,9502017-08-07 HIGH 8.8 CVE-2017-10677 Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.… Ea4500 Firmware after 2.0.36 Fix from $1,9502017-08-06 HIGH 8.8 CVE-2017-12584 There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the… Senayan Library Management System after 8.3.1 Fix from $1,9502017-08-06 HIGH 8.8 CVE-2017-9863 An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site… Sunny Boy 3600 Firmware Mitigation only Fix from $1,9502017-08-05 HIGH 7.5 CVE-2017-12439 SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-s… Flash Slideshow Maker after 5.20 Fix from $1,9502017-08-05 HIGH 8.8 CVE-2017-2138 Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese E… Cs Cart after 4.3.10 Fix from $1,9502017-08-02 HIGH 8.8 CVE-2017-11648 Techroutes TR 1803-3G Wireless Cellular Router/Modem 2.4.25 devices do not possess any protection against a CSRF vulnerability, as demonstrated by a … Tr 1803 3g Firmware Mitigation only Fix from $1,9502017-07-31 HIGH 8.8 CVE-2017-11726 services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrated by c… Manage No fix yet Fix from $1,9502017-07-31 HIGH 8.8 CVE-2016-9714 IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an … Infosphere Master Data Management Server Patch available Fix from $1,9502017-07-31 HIGH 8.8 CVE-2016-9716 IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attack… Infosphere Master Data Management Server Patch available Fix from $1,9502017-07-31 HIGH 8.8 CVE-2017-9489 The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF. Dpc3939b Firmware No fix yet Fix from $1,9502017-07-31 HIGH 8.8 CVE-2017-9490 The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows configurati… Dpc3939b Firmware No fix yet Fix from $1,9502017-07-31 HIGH 8.8 CVE-2017-11646 NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by usin… 4gt101w Software Mitigation only Fix from $1,9502017-07-28 HIGH 8.8 CVE-2017-11679 Cross-Site Request Forgery (CSRF) exists in Hashtopus 1.5g via the password parameter to admin.php in an a=config action. Hashtopus No fix yet Fix from $1,9502017-07-27 HIGH 8.8 CVE-2017-11680 Cross-Site Request Forgery (CSRF) exists in Hashtopussy 0.4.0, allowing an admin password change via users.php. Hashtopussy after 0.4.0 Fix from $1,9502017-07-27 HIGH 8.8 CVE-2017-9413 Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authenticati… Subsonic No fix yet Fix from $1,9502017-07-25 HIGH 8.8 CVE-2017-2273 Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attack… Wmr 433 Firmware after 1.40 Fix from $1,9502017-07-22 HIGH 7.5 CVE-2017-9415 Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authent… Subsonic No fix yet Fix from $1,9502017-07-21 HIGH 8.8 CVE-2015-4639 Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 … Koha Mitigation only Fix from $1,9502017-07-21