Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2014-1615 Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of admini… Carbon Black after 4.1.0 Fix from $1,6002014-04-22 MEDIUM 6.8 CVE-2014-2659 Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to hijack the… Papercut Mf after 14.1 Fix from $1,6002014-04-22 MEDIUM 6.8 CVE-2014-1990 Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 de… E Studio 232 Mitigation only Fix from $1,6002014-04-19 MEDIUM 6.8 CVE-2014-0054EPSS 91% The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resol… Spring Framework after 3.2.7 Fix from $1,6002014-04-17 MEDIUM 6.8 CVE-2013-2706 Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote attackers to hijack the authentic… Stream Video Player Mitigation only Fix from $1,6002014-04-11 MEDIUM 6.8 CVE-2013-2708 Cross-site request forgery (CSRF) vulnerability in the Content Slide plugin 1.4.2 for WordPress allows remote attackers to hijack the authentication … Content Slide Mitigation only Fix from $1,6002014-04-11 MEDIUM 6.8 CVE-2013-2693 Cross-site request forgery (CSRF) vulnerability in the Options in the WP-Print plugin before 2.52 for WordPress allows remote attackers to hijack the… Wp Print after 2.51 Fix from $1,6002014-04-10 MEDIUM 6.8 CVE-2013-2699 Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attackers to hijack the authe… Underconstruction after 1.08 Fix from $1,6002014-04-10 MEDIUM 6.8 CVE-2013-3251 Cross-site request forgery (CSRF) vulnerability in the qTranslate plugin 2.5.34 and earlier for WordPress allows remote attackers to hijack the authe… Qtranslate after 2.5.34 Fix from $1,6002014-04-10 MEDIUM 6.8 CVE-2013-3252 Cross-site request forgery (CSRF) vulnerability in the options admin page in the WP-PostViews plugin before 1.63 for WordPress allows remote attacker… Wp Postviews after 1.62 Fix from $1,6002014-04-10 MEDIUM 6.8 CVE-2012-4921 Multiple cross-site request forgery (CSRF) vulnerabilities in the DVS Custom Notification plugin 1.0.1 and earlier for WordPress allow remote attacke… Dvs Custom Notification Mitigation only Fix from $1,6002014-04-10 MEDIUM 6.8 CVE-2014-2115 Multiple cross-site request forgery (CSRF) vulnerabilities in CERUserServlet pages in Cisco Emergency Responder (ER) 8.6 and earlier allow remote att… Emergency Responder after 8.6 Fix from $1,6002014-04-04 MEDIUM 6.8 CVE-2014-2340 Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication… Xcloner after 3.1.0 Fix from $1,6002014-04-03 MEDIUM 6.8 CVE-2013-7352 Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication o… B2evolution after 4.1.6 Fix from $1,6002014-04-02 MEDIUM 6.8 CVE-2013-4240 Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijac… Hms Testimonials after 2.0.10 Fix from $1,6002014-04-02 MEDIUM 6.8 CVE-2013-7346 Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of administrators f… Symphony after 2.3.1 Fix from $1,6002014-03-27 MEDIUM 6.8 CVE-2014-0885 Cross-site request forgery (CSRF) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote a… Lotus Protector For Mail Security Mitigation only Fix from $1,6002014-03-25 MEDIUM 6.8 CVE-2013-5443 Cross-site request forgery (CSRF) vulnerability in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1… Cognos Express Mitigation only Fix from $1,6002014-03-25 MEDIUM 6.8 CVE-2014-0126 Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5… Moodle after 2.3.11 Fix from $1,6002014-03-24 MEDIUM 6.8 CVE-2014-0873 Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSph… Infosphere Master Data Management Server Mitigation only Fix from $1,6002014-03-16 MEDIUM 5.8 CVE-2014-2249 Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 and SIMATIC S7-1200 CPU PLC dev… Simatic S7 1500 Cpu Firmware after 1.1.2 Fix from $1,6002014-03-16 MEDIUM 6.8 CVE-2013-4057 Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, an… Infosphere Information Server Mitigation only Fix from $1,6002014-03-16 MEDIUM 6.8 CVE-2013-0299 Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote attackers to hijack the auth… Owncloud after 4.0.11 Fix from $1,6002014-03-14 MEDIUM 6.8 CVE-2013-0300 Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to hijack the authentication of user… Owncloud Server Mitigation only Fix from $1,6002014-03-14 MEDIUM 6.8 CVE-2013-0301 Cross-site request forgery (CSRF) vulnerability in apps/calendar/ajax/settings/settimezone in ownCloud before 4.0.12 allows remote attackers to hijac… Owncloud after 4.0.11 Fix from $1,6002014-03-14 MEDIUM 6.8 CVE-2013-4963 Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication… Puppet Enterprise after 3.0.0 Fix from $1,6002014-03-14 MEDIUM 6.8 CVE-2013-1399 Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administration compo… Puppet Enterprise after 2.7.0 Fix from $1,6002014-03-14 MEDIUM 6.8 CVE-2013-6188 Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7.2.2 allows remote attackers to hijack the authen… System Management Homepage Patch available Fix from $1,6002014-03-14 MEDIUM 6.8 CVE-2013-3729 Multiple cross-site request forgery (CSRF) vulnerabilities in Kasseler CMS before 2 r1232 allow remote attackers to hijack the authentication of admi… Kasseler Cms after 2 Fix from $1,6002014-03-13 MEDIUM 6.8 CVE-2013-2754 Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of adm… Umi.cms after 2.9 Fix from $1,6002014-03-11