Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2017-3877 A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct… Unified Communications Manager Mitigation only Fix from $1,6002017-03-17 HIGH 7.5 CVE-2017-6379 Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a … Drupal Mitigation only Fix from $1,9502017-03-16 HIGH 7.1 CVE-2017-6914 CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page. A user can be deleted. Bigtree Cms Patch available Fix from $1,9502017-03-15 HIGH 8.8 CVE-2017-6366 Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijac… Dgn2200 Firmware after 10.0.0.50 Fix from $1,9502017-03-15 CRITICAL 9.8 CVE-2017-6080 An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP A… Zammad after 1.0.3 Fix from $2,3002017-03-13 HIGH 8.8 CVE-2017-6081 A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cr… Zammad after 1.0.3 Fix from $1,9502017-03-13 HIGH 8.8 CVE-2017-6180 Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entir… Kk002 Ip Camera Firmware No fix yet Fix from $1,9502017-03-13 MEDIUM 6.5 CVE-2017-6819 In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive… WordPress after 4.7.2 Fix from $1,6002017-03-12 HIGH 8.0 CVE-2017-5633 Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) chan… Di 524 Firmware No fix yet Fix from $1,9502017-03-06 HIGH 8.8 CVE-2017-6411 Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any p… Dsl 2730u Firmware No fix yet Fix from $1,9502017-03-06 HIGH 8.8 CVE-2015-8814 Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demons… Umbraco Patch available Fix from $1,9502017-03-03 HIGH 8.8 CVE-2016-10206 Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requ… Zoneminder after 1.30.0 Fix from $1,9502017-03-03 HIGH 8.8 CVE-2017-2682 The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery … Ruggedcom Network Management Software after 2.0.2 Fix from $1,9502017-02-27 HIGH 8.8 CVE-2016-9975 IBM Jazz for Service Management 1.1.2.1 and 1.1.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and … Dashboard Application Services Hub Patch available Fix from $1,9502017-02-24 HIGH 8.8 CVE-2017-6127 Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.02 allow … Dg Hr1400 Firmware No fix yet Fix from $1,9502017-02-21 CRITICAL 9.8 CVE-2017-5959 CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token. Genixcms after 1.0.1 Fix from $2,3002017-02-21 MEDIUM 5.7 CVE-2016-4315 Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for req… Carbon Patch available Fix from $1,6002017-02-17 HIGH 8.8 CVE-2016-4311 Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authent… Identity Server Patch available Fix from $1,9502017-02-17 HIGH 8.8 CVE-2016-6033 IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute… Tivoli Storage Manager For Virtual Environments Data Protection For Vmware Patch available Fix from $1,9502017-02-15 HIGH 7.5 CVE-2017-5169 An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior. Multiple Cross Site Request Forgery vulnerabilities have bee… Smart Security Manager after 1.5 Fix from $1,9502017-02-13 HIGH 8.8 CVE-2016-9365 An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2… Nport 5100 Series Firmware after 3.10 Fix from $1,9502017-02-13 CRITICAL 10.0 CVE-2017-5145 An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitat… Vmu C Em Firmware Mitigation only Fix from $2,3002017-02-13 HIGH 7.6 CVE-2017-5165 An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. There is no CSRF Token generated per page and/or per (sensi… Universal Multifunctional Electric Power Quality Meter Firmware Mitigation only Fix from $1,9502017-02-13 HIGH 8.8 CVE-2016-8369 An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application does not sufficiently verify if a request was inte… Jenesys Bas Bridge after 1.1.8 Fix from $1,9502017-02-13 HIGH 8.8 CVE-2016-5809 An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 ser… Ion5000 No fix yet Fix from $1,9502017-02-13 MEDIUM 6.3 CVE-2016-8350 An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmwa… Iologik E1200 Series Firmware after 3.13 Fix from $1,6002017-02-13 MEDIUM 6.3 CVE-2016-5372 Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication … Snap Creator Framework after 4.3.0 Fix from $1,6002017-02-07 HIGH 8.8 CVE-2016-2539 Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of… Atutor after 2.2.1 Fix from $1,9502017-02-07 HIGH 8.8 CVE-2017-5368 ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote atta… Zoneminder No fix yet Fix from $1,9502017-02-06 HIGH 8.8 CVE-2016-6103 IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut… Security Key Lifecycle Manager Patch available Fix from $1,9502017-02-02