Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2013-3086 Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hijack the authentication of adm… N900 Firmware No fix yet Fix from $1,6002014-09-29 MEDIUM 6.8 CVE-2013-3089 Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication o… N300 Firmware No fix yet Fix from $1,6002014-09-29 MEDIUM 6.0 CVE-2014-4816 Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 bef… Websphere Application Server Patch available Fix from $1,6002014-09-23 MEDIUM 6.8 CVE-2014-4865 Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authenticatio… Cacheguardos Mitigation only Fix from $1,6002014-09-10 MEDIUM 6.0 CVE-2014-4785 Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.09… Initiate Master Data Service Patch available Fix from $1,6002014-09-10 MEDIUM 6.0 CVE-2014-3037 Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager b… Rational Rhapsody Design Manager after 4.06 Fix from $1,6002014-09-10 MEDIUM 6.8 CVE-2014-4783 Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.09… Initiate Master Data Service Patch available Fix from $1,6002014-09-10 MEDIUM 6.8 CVE-2014-2390 Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) before 6.1.15.39 7.1.5.x befor… Network Security Manager 6.1.15.39 / 7.1.5.15+ Fix from $1,6002014-08-29 MEDIUM 6.0 CVE-2014-3024 Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5.0.6 and Maximo Asset Manageme… Smartcloud Control Desk Mitigation only Fix from $1,6002014-08-29 MEDIUM 6.8 CVE-2014-3061 Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10… Emptoris Spend Analysis Mitigation only Fix from $1,6002014-08-26 MEDIUM 6.8 CVE-2014-3907 Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote att… Mailpoet Newsletters after 2.6.10 Fix from $1,6002014-08-26 MEDIUM 6.0 CVE-2014-3040 Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 1… Emptoris Spend Analysis Mitigation only Fix from $1,6002014-08-26 MEDIUM 6.8 CVE-2014-5335 Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authenticat… Innovaphone Pbx after 10.00 Fix from $1,6002014-08-25 MEDIUM 6.8 CVE-2014-2633 Cross-site request forgery (CSRF) vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to hijack t… Service Manager Mitigation only Fix from $1,6002014-08-23 MEDIUM 6.8 CVE-2014-5241 The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 accep… Mediawiki after 1.19.17 Fix from $1,6002014-08-22 MEDIUM 6.8 CVE-2014-0641 Cross-site request forgery (CSRF) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to hijack the authenticatio… Rsa Archer Egrc Mitigation only Fix from $1,6002014-08-20 MEDIUM 6.8 CVE-2014-2518 Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hi… Digital Assets Manager Mitigation only Fix from $1,6002014-08-20 MEDIUM 6.8 CVE-2014-5346 Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow remote attackers to hijack th… Disqus Comment System No fix yet Fix from $1,6002014-08-19 MEDIUM 6.8 CVE-2014-5347 Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hi… Disqus Comment System after 2.75 Fix from $1,6002014-08-19 MEDIUM 6.8 CVE-2014-5204 wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce ar… Debian Linux after 3.9.1 Fix from $1,6002014-08-18 MEDIUM 6.8 CVE-2014-5205 wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, whic… WordPress after 3.9.1 Fix from $1,6002014-08-18 MEDIUM 6.8 CVE-2014-0969 Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x b… Infosphere Master Data Management Patch available Fix from $1,6002014-08-17 MEDIUM 6.8 CVE-2012-5683 Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack the authentication of admini… Zpanel after 10.0.1 Fix from $1,6002014-08-14 MEDIUM 6.8 CVE-2014-5199 Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attacke… Wordpress File Upload after 2.4.1 Fix from $1,6002014-08-12 MEDIUM 6.8 CVE-2014-3854 Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication of adminis… Pyplate No fix yet Fix from $1,6002014-08-07 MEDIUM 6.8 CVE-2014-3896 Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote … Acmailer 3.8.17 / 3.9.10+ Fix from $1,6002014-07-29 MEDIUM 6.8 CVE-2014-2974 Cross-site request forgery (CSRF) vulnerability in php/user_account.php in Silver Peak VX through 6.2.4 allows remote attackers to hijack the authent… Vx after 6.2.4 Fix from $1,6002014-07-28 MEDIUM 6.8 CVE-2014-3305 Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers t… Webex Meetings Server after 1.5 Fix from $1,6002014-07-26 MEDIUM 6.8 CVE-2014-5100 Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrator… Omeka after 2.2 Fix from $1,6002014-07-25 MEDIUM 6.0 CVE-2014-2369 Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allo… Ns Series System Program Firmware Mitigation only Fix from $1,6002014-07-24