Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2016-4885 Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attackers to hijack the authenticati… Basercms Patch available Fix from $1,9502017-05-12 HIGH 8.8 CVE-2016-4886 Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authenticati… Basercms Patch available Fix from $1,9502017-05-12 HIGH 8.8 CVE-2016-4887 Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the authenti… Basercms Patch available Fix from $1,9502017-05-12 HIGH 8.8 CVE-2016-9092 The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site r… Content Analysis Mitigation only Fix from $1,9502017-05-11 HIGH 8.8 CVE-2016-5889 IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized … Interact Patch available Fix from $1,9502017-05-10 HIGH 8.8 CVE-2017-5891 ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 have Login Page CSRF and Save Settings CSRF. Rt Ac1750 Firmware Patch available Fix from $1,9502017-05-10 HIGH 8.8 CVE-2017-8874 Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests … Mautic Mitigation only Fix from $1,9502017-05-10 MEDIUM 6.5 CVE-2017-8875 CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL. Clean Login Patch available Fix from $1,6002017-05-10 MEDIUM 6.5 CVE-2017-8848 Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password. Allen Disk Patch available Fix from $1,6002017-05-08 HIGH 8.8 CVE-2017-7431 Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management. Imanager Mitigation only Fix from $1,9502017-05-03 HIGH 8.8 CVE-2017-1194 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou… Websphere Application Server Patch available Fix from $1,9502017-04-28 HIGH 8.8 CVE-2017-2097 Cross-site request forgery (CSRF) vulnerability in Knowledge versions prior to v1.7.0 allows remote attackers to hijack the authentication of adminis… Knowledge after 1.4.1 Fix from $1,9502017-04-28 HIGH 8.8 CVE-2017-2102 Cross-site request forgery (CSRF) vulnerability in Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remot… Appgoat after 3.0.0 Fix from $1,9502017-04-28 HIGH 8.8 CVE-2016-3691 Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method. Kallithea after 0.3.1 Fix from $1,9502017-04-24 MEDIUM 6.5 CVE-2017-8098 e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forge… E107 Patch available Fix from $1,6002017-04-24 HIGH 8.1 CVE-2017-8099 There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a G… Whizz after 1.1 Fix from $1,9502017-04-24 MEDIUM 6.5 CVE-2017-8100 There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings. Copysafe Web Protection after 2.5 Fix from $1,6002017-04-24 HIGH 8.8 CVE-2017-8101 There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request. Serendipity Patch available Fix from $1,9502017-04-24 HIGH 8.8 CVE-2017-7852 D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's s… Dcs 2230l Firmware after 2.13.15 Fix from $1,9502017-04-24 MEDIUM 6.5 CVE-2017-8082 concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking… Concrete Cms No fix yet Fix from $1,6002017-04-24 HIGH 8.8 CVE-2016-0720 Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149. Fedora after 0.9.148 Fix from $1,9502017-04-21 HIGH 8.8 CVE-2017-7951 WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context. Wondercms after 2.0.2 Fix from $1,9502017-04-21 HIGH 8.8 CVE-2017-7990 The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScri… Openmrs Module Reporting Patch available Fix from $1,9502017-04-21 HIGH 8.0 CVE-2016-1161 Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500). Password Manager Pro after 8.5 Fix from $1,9502017-04-20 HIGH 8.8 CVE-2016-3734 Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.… Moodle Patch available Fix from $1,9502017-04-20 HIGH 8.8 CVE-2016-5401 Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for re… Jboss Bpm Suite Mitigation only Fix from $1,9502017-04-20 HIGH 8.8 CVE-2017-5156 A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client requ… Wonderware Intouch Access Anywhere after 11.5.2 Fix from $1,9502017-04-20 HIGH 8.8 CVE-2017-7881 BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the require… Bigtree Cms after 4.2.17 Fix from $1,9502017-04-15 HIGH 8.8 CVE-2017-7877 CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations. Flatcore Cms Patch available Fix from $1,9502017-04-14 HIGH 8.8 CVE-2015-7563 Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticat… Teampass after 2.1.24.0 Fix from $1,9502017-04-12