Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2017-9930 Cross-Site Request Forgery (CSRF) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by a request to ajax.cgi tha… Dx 350 Firmware No fix yet Fix from $1,9502017-07-21 HIGH 8.8 CVE-2017-1218 IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions t… Bigfix Platform Mitigation only Fix from $1,9502017-07-19 HIGH 8.0 CVE-2016-7507 Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creat… Glpi Mitigation only Fix from $1,9502017-07-19 HIGH 8.8 CVE-2017-10961 REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components. Redcap after 7.5.0 Fix from $1,9502017-07-18 HIGH 8.8 CVE-2017-9810 There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix … Anti Virus For Linux Server after 8.0.3.297 Fix from $1,9502017-07-17 HIGH 8.8 CVE-2017-7666 Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks. Openmeetings Mitigation only Fix from $1,9502017-07-17 HIGH 8.8 CVE-2017-1000069 CSRF in Bitly oauth2_proxy 2.1 during authentication flow Oauth2 Proxy Patch available Fix from $1,9502017-07-17 HIGH 8.8 CVE-2017-1000008 Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users t… Chyrp Lite Patch available Fix from $1,9502017-07-17 HIGH 8.8 CVE-2017-11193 Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute,… Pulse Connect Secure Mitigation only Fix from $1,9502017-07-12 HIGH 8.8 CVE-2017-11196 Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attac… Pulse Connect Secure Mitigation only Fix from $1,9502017-07-12 HIGH 8.8 CVE-2017-2238 Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway H… Hem Gw16a Firmware after 1.2.0 Fix from $1,9502017-07-07 HIGH 8.8 CVE-2017-2244 Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of adm… Mfc J960dwn Firmware Mitigation only Fix from $1,9502017-07-07 HIGH 8.8 CVE-2017-2223 Cross-site request forgery (CSRF) vulnerability in TS-WPTCAM, TS-PTCAM, TS-PTCAM/POE, TS-WLC2, TS-WLCE, TS-WRLC firmware version 1.19 and earlier and… Ts Wptcam Camera Firmware after 1.19 Fix from $1,9502017-07-07 HIGH 8.8 CVE-2017-7404 On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the m… Dir 615 after 20.12ptb01 Fix from $1,9502017-07-07 HIGH 8.8 CVE-2017-4998 EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is potentially affected by a cross-site request forgery vulnerability. A remote l… Rsa Archer Egrc Mitigation only Fix from $1,9502017-07-07 HIGH 8.8 CVE-2017-5943 Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cro… Request Tracker Mitigation only Fix from $1,9502017-07-03 HIGH 7.1 CVE-2017-6038 A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web applicat… Gecko Lite Managed Switch Firmware after 2.0.00 Fix from $1,9502017-06-30 HIGH 8.8 CVE-2017-6042 A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versio… Airlink Raven Xe Firmware Mitigation only Fix from $1,9502017-06-30 HIGH 8.8 CVE-2017-10678 Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to… Piwigo after 2.9.1 Fix from $1,9502017-06-29 HIGH 8.8 CVE-2017-10680 Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to… Piwigo after 2.9.1 Fix from $1,9502017-06-29 HIGH 8.8 CVE-2017-10681 Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to… Piwigo after 2.9.1 Fix from $1,9502017-06-29 HIGH 8.8 CVE-2017-5528 Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-sit… Jasperreports Server after 6.3.0 Fix from $1,9502017-06-29 HIGH 8.8 CVE-2017-6086 Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.15 allow remote attackers to h… Vimbadmin No fix yet Fix from $1,9502017-06-27 HIGH 8.8 CVE-2016-1000218 Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an … Kibana Reporting Mitigation only Fix from $1,9502017-06-16 HIGH 8.8 CVE-2017-9673 In SimpleCE 2.3.0, a CSRF vulnerability can be exploited to add an administrator account (via the index.php/user/new URI) or change its settings (via… Simplece after 2.3.0 Fix from $1,9502017-06-15 HIGH 8.8 CVE-2017-6659 A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to condu… Prime Collaboration Assurance Mitigation only Fix from $1,9502017-06-13 HIGH 8.8 CVE-2016-4907 Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors. Garoon Mitigation only Fix from $1,9502017-06-09 HIGH 8.8 CVE-2016-7809 Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows remote attackers to hijack the authentica… Cg Wlr300nx Firmware after 1.20 Fix from $1,9502017-06-09 HIGH 8.8 CVE-2016-7822 Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackers to hijac… Wnc01wh Firmware after 1.0.0.8 Fix from $1,9502017-06-09 HIGH 8.8 CVE-2015-1786 Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers. Zend Framework Mitigation only Fix from $1,9502017-06-08