Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2014-0621 Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to hijack the a… Tc7200 Firmware No fix yet Fix from $1,6002014-01-08 MEDIUM 6.8 CVE-2013-6992 Cross-site request forgery (CSRF) vulnerability in askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin 3.0 and earlier for WordPres… Firefox Adsense after 3.0 Fix from $1,6002014-01-03 MEDIUM 6.8 CVE-2013-7256 Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.2 allows remote attackers to hijack the authentication of unspecified victims v… Opsview after 4.4.1 Fix from $1,6002014-01-03 MEDIUM 6.8 CVE-2013-7223 Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspe… Fat Free Crm after 0.12.0 Fix from $1,6002014-01-02 MEDIUM 6.8 CVE-2013-7251 Multiple cross-site request forgery (CSRF) vulnerabilities in ProjectForge before 5.3 allow remote attackers to hijack the authentication of arbitrar… Projectforge after 5.2 Fix from $1,6002014-01-02 MEDIUM 6.8 CVE-2013-7209 Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authenticat… Jforum No fix yet Fix from $1,6002013-12-30 MEDIUM 5.4 CVE-2013-5039 Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to … Hotbox Router Firmware No fix yet Fix from $1,6002013-12-30 MEDIUM 6.8 CVE-2013-7233 Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows … WordPress after 2.0.11 Fix from $1,6002013-12-30 MEDIUM 6.8 CVE-2013-4405 Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers t… Enterprise Mrg Mitigation only Fix from $1,6002013-12-23 MEDIUM 6.8 CVE-2013-2628 Multiple cross-site request forgery (CSRF) vulnerabilities in action.php in Leed (Light Feed), possibly before 1.5 Stable, allow remote attackers to … Leed after 1.4 Fix from $1,6002013-12-21 MEDIUM 6.8 CVE-2013-6976 Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers to hijack the authentication o… Epc3925 No fix yet Fix from $1,6002013-12-19 MEDIUM 6.8 CVE-2013-6883 Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack … Ditto Forensic Fieldstation Firmware after 2013oct15a Fix from $1,6002013-12-17 MEDIUM 6.8 CVE-2013-6192 Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration before 9 allows remote attackers to hijack the authentication of unspe… Operations Orchestration after 7.5 Fix from $1,6002013-12-17 MEDIUM 6.8 CVE-2013-6710 Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Training Center allows remote attackers to hijack the authentication of unspecified vi… Webex Training Center Mitigation only Fix from $1,6002013-12-14 MEDIUM 6.8 CVE-2013-4000 Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authenticati… Cognos Command Center after 10.1 Fix from $1,6002013-12-14 MEDIUM 6.8 CVE-2012-5394 Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.2… Mediawiki after 1.19.8 Fix from $1,6002013-12-13 MEDIUM 6.8 CVE-2013-2752 Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 al… Raidiator 4.1.12 / 4.2.24+ Fix from $1,6002013-12-12 HIGH 8.3 CVE-2013-7043 Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote… Scientific Atlanta Dpr\/epr2320 Firmware No fix yet Fix from $1,9502013-12-10 MEDIUM 6.8 CVE-2013-5355 Multiple cross-site request forgery (CSRF) vulnerabilities in Sharetronix 3.1.1 allow remote attackers to hijack the authentication of administrators… Sharetronix Mitigation only Fix from $1,6002013-12-09 MEDIUM 6.8 CVE-2013-6852 Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication of adminis… 2620 24 Poe\+ Switch No fix yet Fix from $1,6002013-11-22 MEDIUM 6.8 CVE-2013-5993 Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.0 allows remote attackers to hijack the authentication of arbit… Ec Cube Patch available Fix from $1,6002013-11-21 MEDIUM 6.8 CVE-2013-6173 Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 b… Document Sciences Xpression No fix yet Fix from $1,6002013-11-21 MEDIUM 6.8 CVE-2013-6826 cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which… Fortianalyzer Firmware after 5.0.4 Fix from $1,6002013-11-20 MEDIUM 6.8 CVE-2013-5730 Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DSL-2740B Gateway with firmware EU_1.00 allow remote attackers to hijack the aut… Dsl 2740b Firmware No fix yet Fix from $1,6002013-11-20 MEDIUM 6.8 CVE-2013-3095 Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to … Dir865l Firmware after 1.05 Fix from $1,6002013-11-20 MEDIUM 6.8 CVE-2013-6797 Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for WordPress allo… Blue Wrench Video Widget after 1.0.5 Fix from $1,6002013-11-19 MEDIUM 6.8 CVE-2013-3694 BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, whic… Blackberry Link after 1.2.0.28 Fix from $1,6002013-11-18 MEDIUM 6.8 CVE-2013-4555 Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP before 2.1.24 allows remote attackers to hijack the authenticatio… Spip after 2.1.23 Fix from $1,6002013-11-18 MEDIUM 6.8 CVE-2013-6357 Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the … Tomcat after 5.5.25 Fix from $1,6002013-11-13 MEDIUM 6.8 CVE-2013-5726 Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attac… Tweetbot No fix yet Fix from $1,6002013-11-12