Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.0 CVE-2016-9991 IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau… Sterling Selling And Fulfillment Foundation Patch available Fix from $1,9502017-06-08 HIGH 8.8 CVE-2017-9517 atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV. Atmail after 7.8.0.1 Fix from $1,9502017-06-08 HIGH 8.8 CVE-2017-9518 atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails. Atmail after 7.8.0.1 Fix from $1,9502017-06-08 HIGH 8.8 CVE-2017-9519 atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account. Atmail after 7.8.0.1 Fix from $1,9502017-06-08 HIGH 8.8 CVE-2017-9444 BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/… Bigtree Cms after 4.2.18 Fix from $1,9502017-06-05 HIGH 8.8 CVE-2017-8836 CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-bui… B305hw2 Firmware No fix yet Fix from $1,9502017-06-05 HIGH 8.8 CVE-2016-8229 A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server… Lenovo Service Bridge Mitigation only Fix from $1,9502017-06-04 HIGH 8.8 CVE-2017-9379 Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and th… Bigtree Cms after 4.2.18 Fix from $1,9502017-06-02 HIGH 8.8 CVE-2017-9365 CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false… Bigtree Cms after 4.2.18 Fix from $1,9502017-06-02 HIGH 8.8 CVE-2017-7917 A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Vers… Oncell G3110 Hspa Firmware after 1.4 Fix from $1,9502017-05-29 HIGH 8.8 CVE-2017-9033 Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authe… Serverprotect Patch available Fix from $1,9502017-05-26 HIGH 8.8 CVE-2015-3191 With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or e… Cf Release after 209 Fix from $1,9502017-05-25 HIGH 8.0 CVE-2017-5657 Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the … Archiva after 2.2.1 Fix from $1,9502017-05-22 HIGH 8.8 CVE-2016-4854 Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijack the authentication of admin… L 04d Firmware Mitigation only Fix from $1,9502017-05-22 HIGH 8.8 CVE-2016-4904 Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote att… Olivecart after 3.1.7 Fix from $1,9502017-05-22 HIGH 8.8 CVE-2017-6634 A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote atta… Industrial Ethernet 1000 Series Firmware Mitigation only Fix from $1,9502017-05-22 MEDIUM 6.5 CVE-2017-7620 MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpret… Mantisbt after 1.3.10 Fix from $1,6002017-05-21 HIGH 8.6 CVE-2017-9062 In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API. WordPress after 4.7.4 Fix from $1,9502017-05-18 HIGH 8.8 CVE-2017-9064 In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not requi… WordPress after 4.7.4 Fix from $1,9502017-05-18 HIGH 8.8 CVE-2016-3403 Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers t… Zimbra Collaboration Suite after 8.6.0 Fix from $1,9502017-05-17 HIGH 8.8 CVE-2017-7661 Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty… Cxf Fediz after 1.4.0 Fix from $1,9502017-05-16 HIGH 8.8 CVE-2017-7662 Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows c… Cxf Fediz after 1.3.2 Fix from $1,9502017-05-16 HIGH 8.8 CVE-2017-8928 mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF. Mailcow\ Patch available Fix from $1,9502017-05-14 HIGH 8.8 CVE-2017-8930 Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of ad… Simple Invoices Mitigation only Fix from $1,9502017-05-14 HIGH 8.8 CVE-2016-4876 Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of admini… Basercms Patch available Fix from $1,9502017-05-12 HIGH 8.8 CVE-2016-4878 Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of admini… Basercms Patch available Fix from $1,9502017-05-12 HIGH 8.8 CVE-2016-4879 Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authenticati… Basercms after 3.0.10 Fix from $1,9502017-05-12 HIGH 8.8 CVE-2016-4881 Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authenticati… Basercms Patch available Fix from $1,9502017-05-12 HIGH 8.8 CVE-2016-4882 Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of admini… Basercms Patch available Fix from $1,9502017-05-12 HIGH 8.8 CVE-2016-4884 Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authenticati… Basercms Patch available Fix from $1,9502017-05-12