Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2016-4891 Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator t… Setucocms Mitigation only Fix from $1,9502017-04-12 HIGH 8.8 CVE-2016-8718 An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running f… Awk 3131a Firmware No fix yet Fix from $1,9502017-04-12 HIGH 8.8 CVE-2016-4319 Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings. Jira after 7.1.8 Fix from $1,9502017-04-10 HIGH 8.8 CVE-2015-8255 AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi. Axis Communications Firmware No fix yet Fix from $1,9502017-04-10 HIGH 8.0 CVE-2017-7571 public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. Faveo Helpdesk No fix yet Fix from $1,9502017-04-06 HIGH 8.8 CVE-2017-7446 HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges. Helpdezk Patch available Fix from $1,9502017-04-05 HIGH 8.8 CVE-2017-7447 HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. Helpdezk Patch available Fix from $1,9502017-04-05 HIGH 8.8 CVE-2016-6100 IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is … Disposal And Governance Management For It Mitigation only Fix from $1,9502017-04-05 HIGH 8.8 CVE-2017-7398 D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted acti… Dir 615 Firmware No fix yet Fix from $1,9502017-04-04 HIGH 8.8 CVE-2016-10313 Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.0… Al3g Firmware No fix yet Fix from $1,9502017-04-03 HIGH 8.8 CVE-2014-9136 Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the u… Fusionmanager Mitigation only Fix from $1,9502017-04-02 HIGH 8.8 CVE-2014-9137 Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG22… Fusionmanager Mitigation only Fix from $1,9502017-04-02 HIGH 8.8 CVE-2014-9694 Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, T… Tecal Rh1288 V2 Firmware Mitigation only Fix from $1,9502017-04-02 HIGH 8.8 CVE-2016-8917 IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz… Sterling Selling And Fulfillment Foundation Patch available Fix from $1,9502017-03-31 HIGH 8.8 CVE-2017-2688 The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privil… Ruggedcom Rox I after 2.9.0 Fix from $1,9502017-03-29 HIGH 8.8 CVE-2016-9127 Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF atta… Revive Adserver after 3.2.2 Fix from $1,9502017-03-28 HIGH 8.8 CVE-2016-9455 Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable t… Revive Adserver after 3.2.2 Fix from $1,9502017-03-28 HIGH 8.8 CVE-2016-9456 Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interfa… Revive Adserver after 3.2.2 Fix from $1,9502017-03-28 HIGH 8.8 CVE-2017-6002 Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body par… Subrion Cms Mitigation only Fix from $1,9502017-03-27 HIGH 8.8 CVE-2017-6066 Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title… Subrion Cms Mitigation only Fix from $1,9502017-03-27 HIGH 8.8 CVE-2017-6068 Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter. Subrion Cms Mitigation only Fix from $1,9502017-03-27 HIGH 8.8 CVE-2017-6069 Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter. Subrion Cms Mitigation only Fix from $1,9502017-03-27 HIGH 8.8 CVE-2015-8623 The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in cons… Mediawiki after 1.23.11 Fix from $1,9502017-03-23 HIGH 8.8 CVE-2015-8624 The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.2… Mediawiki after 1.23.11 Fix from $1,9502017-03-23 HIGH 8.8 CVE-2016-5758 A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by re… Access Manager Mitigation only Fix from $1,9502017-03-23 HIGH 8.8 CVE-2017-5874 CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or… Dir 600m Firmware after 1.0.1 Fix from $1,9502017-03-22 HIGH 8.8 CVE-2016-4504 A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlim… Weblog Mitigation only Fix from $1,9502017-03-21 HIGH 8.8 CVE-2016-4928 Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Spac… Junos Space after 15.2 Fix from $1,9502017-03-20 HIGH 8.8 CVE-2017-6803 Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 a… Ftp Voyager No fix yet Fix from $1,9502017-03-20 HIGH 8.8 CVE-2017-7178 CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitr… Debian Linux 1.3.14+ Fix from $1,9502017-03-18