Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2012-5950 Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers … Tririga Application Platform Mitigation only Fix from $1,6002013-04-23 MEDIUM 6.8 CVE-2013-2697 Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the auth… Wp Downloadmanager after 1.60 Fix from $1,6002013-04-19 MEDIUM 6.8 CVE-2012-3532 Cross-site request forgery (CSRF) vulnerability in the GateIn Portal component in JBoss Enterprise Portal Platform 5.2.2 and earlier allows remote at… Jboss Enterprise Portal Platform after 5.2.2 Fix from $1,6002013-04-12 MEDIUM 6.8 CVE-2012-6134 Cross-site request forgery (CSRF) vulnerability in the omniauth-oauth2 gem 1.1.1 and earlier for Ruby allows remote attackers to hijack the authentic… Omniauth Oauth2 1.1.1+ Fix from $1,6002013-04-09 HIGH 7.5 CVE-2013-2778 Cross-site request forgery (CSRF) vulnerability in addressbook/register/delete_user.php in PHP Address Book 8.2.5 allows remote attackers to hijack t… Php Address Book Mitigation only Fix from $1,9502013-04-09 HIGH 10.0 CVE-2013-2762 The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remot… Magelis Xbt Hmi Mitigation only Fix from $1,9502013-04-04 MEDIUM 6.8 CVE-2013-0663EPSS 6% Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0… Modicon Quantum Plc No fix yet Fix from $1,6002013-04-04 MEDIUM 6.8 CVE-2013-0532 Cross-site request forgery (CSRF) vulnerability in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x … Security Appscan Mitigation only Fix from $1,6002013-03-29 MEDIUM 6.8 CVE-2013-0452 Cross-site request forgery (CSRF) vulnerability in the Software Use Analysis (SUA) application before 1.3.3 in IBM Tivoli Endpoint Manager 8.2 allows… Software Use Analysis after 1.3.2 Fix from $1,6002013-03-29 MEDIUM 6.8 CVE-2012-5216 Cross-site request forgery (CSRF) vulnerability on HP ProCurve 1700-8 (aka J9079A) switches with software before VA.02.09 and 1700-24 (aka J9080A) sw… Procurve Switch Software Mitigation only Fix from $1,6002013-03-28 MEDIUM 5.1 CVE-2013-0320 Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-r… Taxonomy Manager Patch available Fix from $1,6002013-03-27 MEDIUM 6.0 CVE-2013-0489 Cross-site request forgery (CSRF) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote authenticated us… Lotus Domino Mitigation only Fix from $1,6002013-03-27 MEDIUM 6.8 CVE-2013-0126 Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 all… Fios Actiontec Mi424wr Gen31 Router Firmware No fix yet Fix from $1,6002013-03-21 MEDIUM 6.8 CVE-2013-0717 Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, A… Atermwm3450rn Mitigation only Fix from $1,6002013-03-19 MEDIUM 6.8 CVE-2013-0207 Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the a… Mark Complete Mitigation only Fix from $1,6002013-03-19 MEDIUM 6.8 CVE-2013-0327 Cross-site request forgery (CSRF) vulnerability in Jenkins master in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to hijack th… Jenkins after 1.501 Fix from $1,6002013-03-19 MEDIUM 6.8 CVE-2013-0205 Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 … Restful Web Services 7.x-1.2+ Fix from $1,6002013-03-19 HIGH 7.6 CVE-2013-1468EPSS 6% Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authenti… Piwigo after 2.4.6 Fix from $1,9502013-03-14 MEDIUM 6.8 CVE-2013-1153 Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authenticati… Prime Infrastructure Mitigation only Fix from $1,6002013-03-07 MEDIUM 6.8 CVE-2012-5763 Cross-site request forgery (CSRF) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote attackers to… Netezza Mitigation only Fix from $1,6002013-02-20 MEDIUM 6.8 CVE-2013-1128 Multiple cross-site request forgery (CSRF) vulnerabilities in the server in Cisco Unified MeetingPlace before 7.1(2.2000) allow remote attackers to h… Unified Meetingplace after 7.1 Fix from $1,6002013-02-15 MEDIUM 6.8 CVE-2013-1639 Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism v… Opera Browser after 12.12 Fix from $1,6002013-02-08 MEDIUM 6.8 CVE-2013-1120 Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the a… Unity Express Software after 7.4 Fix from $1,6002013-02-06 MEDIUM 5.1 CVE-2013-0214 Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x … Samba Mitigation only Fix from $1,6002013-02-02 MEDIUM 6.8 CVE-2012-6103 Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x befo… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 6.8 CVE-2013-0460 Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 … Websphere Application Server Mitigation only Fix from $1,6002013-01-27 MEDIUM 6.8 CVE-2012-6518 Cross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authentication of administrators for … Diy Cms No fix yet Fix from $1,6002013-01-24 MEDIUM 6.8 CVE-2012-6508 Multiple cross-site request forgery (CSRF) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to hijack the authentication of admi… Car Portal No fix yet Fix from $1,6002013-01-24 MEDIUM 6.8 CVE-2012-1922 Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the authentication of administrators … Wlm 2501 Mitigation only Fix from $1,6002013-01-24 MEDIUM 6.8 CVE-2013-1109 Cross-site request forgery (CSRF) vulnerability in testingLibraryAction.do in the Training Center testing library in Cisco WebEx Training Center allo… Webex Training Center Mitigation only Fix from $1,6002013-01-17