Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2014-9340 Multiple cross-site request forgery (CSRF) vulnerabilities in the wpCommentTwit plugin 0.5 and earlier for WordPress allow remote attackers to hijack… Wpcommenttwit after 0.5 Fix from $1,6002014-12-19 MEDIUM 6.8 CVE-2014-9339 Multiple cross-site request forgery (CSRF) vulnerabilities in the SPNbabble plugin 1.4.1 and earlier for WordPress allow remote attackers to hijack t… Spnbabble No fix yet Fix from $1,6002014-12-19 MEDIUM 6.8 CVE-2014-9337 Multiple cross-site request forgery (CSRF) vulnerabilities in the Mikiurl Wordpress Eklentisi plugin 2.0 and earlier for WordPress allow remote attac… Mikiurl Wordpress Eklentisi after 2.0 Fix from $1,6002014-12-19 MEDIUM 6.8 CVE-2014-9338 Multiple cross-site request forgery (CSRF) vulnerabilities in the O2Tweet plugin 0.0.4 and earlier for WordPress allow remote attackers to hijack the… O2tweet after 0.0.4 Fix from $1,6002014-12-19 MEDIUM 6.8 CVE-2014-9336 Multiple cross-site request forgery (CSRF) vulnerabilities in the iTwitter plugin 0.04 and earlier for WordPress allow remote attackers to hijack the… Itwitter after 0.04 Fix from $1,6002014-12-19 MEDIUM 6.8 CVE-2014-9335 Multiple cross-site request forgery (CSRF) vulnerabilities in the DandyID Services plugin 1.5.9 and earlier for WordPress allow remote attackers to h… Dandyid Services after 1.5.9 Fix from $1,6002014-12-19 MEDIUM 6.8 CVE-2014-6077 Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x be… Security Access Manager For Web Mitigation only Fix from $1,6002014-12-18 MEDIUM 6.8 CVE-2014-5437 Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow… Touchstone Tg862g\/ct Firmware after 7.6.59s.ct Fix from $1,6002014-12-17 MEDIUM 6.8 CVE-2014-8246 Cross-site request forgery (CSRF) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote atta… Release Automation after 4.7.1 Fix from $1,6002014-12-16 MEDIUM 6.8 CVE-2014-9385 Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbitrary use… Zenoss Core Mitigation only Fix from $1,6002014-12-15 MEDIUM 6.8 CVE-2014-6253 Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hijack the authentication of arb… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 MEDIUM 6.0 CVE-2014-3058 Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated user… Websphere Datapower Xc10 Appliance Firmware Mitigation only Fix from $1,6002014-12-11 MEDIUM 6.8 CVE-2014-7809 Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mecha… Struts No fix yet Fix from $1,6002014-12-10 MEDIUM 6.8 CVE-2014-9344 Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authentication of administrators f… Snowfox Content Management System after 1.0 Fix from $1,6002014-12-08 MEDIUM 6.8 CVE-2014-9300 Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Communit… Alfresco after 5.0.a Fix from $1,6002014-12-07 MEDIUM 6.8 CVE-2014-9129 Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers t… Cm Download Manager after 2.0.6 Fix from $1,6002014-12-05 MEDIUM 6.8 CVE-2014-8773 MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CS… Modx Revolution No fix yet Fix from $1,6002014-12-03 MEDIUM 6.8 CVE-2014-8771 Multiple cross-site request forgery (CSRF) vulnerabilities in the admin area in X3 CMS 0.5.1 and 0.5.1.1 allow remote attackers to hijack the authent… X3 Cms No fix yet Fix from $1,6002014-12-03 MEDIUM 6.8 CVE-2014-8429 Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows remote attackers to hijack t… Xepan Cms after 1.0.1 Fix from $1,6002014-11-28 MEDIUM 6.8 CVE-2014-4829 Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch… Qradar Vulnerability Manager Patch available Fix from $1,6002014-11-28 MEDIUM 6.8 CVE-2014-9104 Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow … Openvpn Access Server after 1.5.6 Fix from $1,6002014-11-26 MEDIUM 6.8 CVE-2014-9101 Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attac… Skadate Lite No fix yet Fix from $1,6002014-11-26 MEDIUM 6.8 CVE-2014-9099 Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authenticatio… Whydowork Adsense No fix yet Fix from $1,6002014-11-26 MEDIUM 6.8 CVE-2014-9033 Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authe… WordPress Patch available Fix from $1,6002014-11-25 MEDIUM 6.8 CVE-2014-7838 Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and … Moodle after 2.4.11 Fix from $1,6002014-11-24 MEDIUM 6.8 CVE-2014-7836 Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.… Moodle after 2.4.11 Fix from $1,6002014-11-24 MEDIUM 6.8 CVE-2014-5395 Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R… E5180s 22 Firmware No fix yet Fix from $1,6002014-11-21 MEDIUM 6.8 CVE-2014-9027 Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators … Zxdsl 831cii No fix yet Fix from $1,6002014-11-20 MEDIUM 6.8 CVE-2014-9019 Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators … Zxdsl No fix yet Fix from $1,6002014-11-20 MEDIUM 6.8 CVE-2014-9003 Cross-site request forgery (CSRF) vulnerability in Lantronix xPrintServer allows remote attackers to hijack the authentication of administrators for … Xprintserver No fix yet Fix from $1,6002014-11-20