Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2014-3015 Cross-site request forgery (CSRF) vulnerability in the Web player in IBM Sametime Proxy Server and Web Client 9.0 through 9.0.0.1 allows remote attac… Sametime Proxy Server And Web Client Mitigation only Fix from $1,6002014-05-26 MEDIUM 6.8 CVE-2014-3267 Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attackers to hijack the … Security Manager after 4.6 Fix from $1,6002014-05-26 MEDIUM 6.8 CVE-2013-2713 Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication… Krisonav after 3.0.1 Fix from $1,6002014-05-23 MEDIUM 6.8 CVE-2013-2107 Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authent… Mail On Update after 5.1.0 Fix from $1,6002014-05-23 MEDIUM 6.8 CVE-2014-3843 Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the auth… Search Everything after 8.1 Fix from $1,6002014-05-22 MEDIUM 6.8 CVE-2014-3845 Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the aut… Color Picker after 1.1 Fix from $1,6002014-05-22 MEDIUM 6.8 CVE-2014-3792 Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authent… 450tc2 Router Firmware No fix yet Fix from $1,6002014-05-20 MEDIUM 6.8 CVE-2014-3760 Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP 1150 with firmware 1.2.94 allow remote attackers to hijack the authenticatio… Dap 1150 Firmware No fix yet Fix from $1,6002014-05-16 MEDIUM 6.8 CVE-2014-0933 Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Information Server Metadata Workbench 8.1 through 9.1 allows remote attackers to hi… Infosphere Information Server Metadata Workbench Mitigation only Fix from $1,6002014-05-16 MEDIUM 6.8 CVE-2013-7376 Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to hijack the auth… Openx No fix yet Fix from $1,6002014-05-14 MEDIUM 6.8 CVE-2013-2700 Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 for WordPress allows remote at… Wp125 after 1.4.9 Fix from $1,6002014-05-14 MEDIUM 6.8 CVE-2013-2034 Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and … Jenkins after 1.513 Fix from $1,6002014-05-14 MEDIUM 6.8 CVE-2013-4562 The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site reque… Omniauth Facebook Patch available Fix from $1,6002014-05-13 MEDIUM 6.8 CVE-2013-2692 Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack th… Openvpn Access Server after 1.8.4 Fix from $1,6002014-05-13 MEDIUM 6.8 CVE-2013-2705 Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers … Wordpress Simple Paypal Shopping Cart after 3.5 Fix from $1,6002014-05-13 MEDIUM 6.8 CVE-2014-2989 Cross-site request forgery (CSRF) vulnerability in Open Assessment Technologies TAO 2.5.6 allows remote attackers to hijack the authentication of adm… Tao No fix yet Fix from $1,6002014-05-13 MEDIUM 6.8 CVE-2012-6342 Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication o… Confluence Server No fix yet Fix from $1,6002014-05-13 MEDIUM 6.8 CVE-2014-3454 Cross-site request forgery (CSRF) vulnerability in Special:CreateCategory in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.… Mediawiki after 1.19.9 Fix from $1,6002014-05-12 MEDIUM 6.8 CVE-2014-3455 Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) CreateProperty, (2) CreateTemplate, (3) CreateForm, and (4) CreateClass special… Mediawiki after 1.19.9 Fix from $1,6002014-05-12 MEDIUM 6.8 CVE-2013-5748 Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to hi… Simplerisk after 20130915-001 Fix from $1,6002014-05-12 MEDIUM 6.0 CVE-2014-0944 Cross-site request forgery (CSRF) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, … Operational Decision Manager Mitigation only Fix from $1,6002014-05-09 MEDIUM 6.8 CVE-2014-3115 Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before 5.2.0 allow remote attackers… Fortiweb after 5.1.4 Fix from $1,6002014-05-08 MEDIUM 6.8 CVE-2014-2190 Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wireless (aka BAC-TW) allows remo… Broadband Access Center Telco Wireless Software Mitigation only Fix from $1,6002014-05-07 MEDIUM 6.8 CVE-2014-2916 Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers to hijack… Phplist after 3.0.5 Fix from $1,6002014-05-05 MEDIUM 6.8 CVE-2014-2186 Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server allows remote attackers to hijack the authenticat… Webex Meetings Server Mitigation only Fix from $1,6002014-04-30 MEDIUM 6.8 CVE-2013-7259 Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for r… Neo4j Mitigation only Fix from $1,6002014-04-29 HIGH 7.6 CVE-2014-2579EPSS 6% Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication … Xcloner after 3.5 Fix from $1,9502014-04-25 MEDIUM 6.8 CVE-2013-4726 Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other vers… Cm3 Acora Content Management System No fix yet Fix from $1,6002014-04-25 MEDIUM 6.8 CVE-2013-5954 Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of adminis… Revive Adserver after 3.0.4 Fix from $1,6002014-04-25 MEDIUM 6.8 CVE-2014-2327 Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users fo… Debian Linux after 0.8.8b Fix from $1,6002014-04-23