Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2012-0286
Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspec…
Webnetwork
after 6.0.7.0
MEDIUM 6.8
CVE-2011-3668
Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the aut…
Bugzilla
No fix yet
MEDIUM 6.8
CVE-2011-3669
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the a…
Bugzilla
No fix yet
MEDIUM 6.8
CVE-2011-5011
Multiple cross-site request forgery (CSRF) vulnerabilities in xt:Commerce 3.0.4 SP2.1 and possibly earlier allow remote attackers to hijack the authe…
Xt Commerce
Mitigation only
MEDIUM 6.8
CVE-2011-3836
Multiple cross-site request forgery (CSRF) vulnerabilities in Wuzly 2.0 allow remote attackers to hijack the authentication of administrators for req…
Wuzly
Mitigation only
MEDIUM 6.8
CVE-2011-4837
Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authenti…
Homeseer Hs2
Mitigation only
MEDIUM 6.8
CVE-2011-3636
Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authenticat…
Freeipa
after 2.1.3
MEDIUM 6.8
CVE-2011-4498
Cross-site request forgery (CSRF) vulnerability in the web console in Zenprise Device Manager 6.x through 6.1.8 allows remote attackers to hijack the…
Zenprise Device Manager
Patch available
MEDIUM 6.8
CVE-2011-2773
Cross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1 allows remote attackers to hijack the authentication of administrators for req…
Mahara
after 1.4.0
MEDIUM 6.8
CVE-2011-3994
Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earl…
Autotagging
after 5.251
HIGH 9.3
CVE-2011-4005
Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521…
Small Business Srp521w
after 1.02.01_mr2
MEDIUM 6.8
CVE-2011-1364
Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console)…
App Engine Python Sdk
after 1.5.3
MEDIUM 6.8
CVE-2011-4173
Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authentication …
Smf
Mitigation only
MEDIUM 6.8
CVE-2011-4140
The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary…
Django
after 1.2.6
MEDIUM 6.8
CVE-2010-4881
Multiple cross-site request forgery (CSRF) vulnerabilities in calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote attackers to hijack the a…
Apphp Calendar
No fix yet
MEDIUM 6.8
CVE-2011-2191
Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of a…
Cherokee
after 1.2.98
MEDIUM 6.8
CVE-2011-1911
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remo…
Jasperreports Server Community Project
Mitigation only
MEDIUM 6.8
CVE-2011-3381
Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified victims v…
Phorum
after 5.2.15
MEDIUM 6.8
CVE-2011-1341
Cross-site request forgery (CSRF) vulnerability in Aimluck Aipo before 4.0.4.0, and Aipo for ASP before 4.0.4.0, allows remote attackers to hijack th…
Aipo
after 4.0.3.0
MEDIUM 6.8
CVE-2011-0551
Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.60…
Endpoint Protection
Mitigation only
MEDIUM 6.8
CVE-2011-2522EPSS 10%
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attack…
Debian Linux
3.3.16 / 3.4.14+
MEDIUM 6.8
CVE-2009-4139
A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authent…
Network Satellite Server
Patch available
MEDIUM 6.8
CVE-2010-3271
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Applicat…
Websphere Application Server
after 7.0.0.13
MEDIUM 6.8
CVE-2011-2753
Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of …
Squirrelmail
after 1.4.21
MEDIUM 6.8
CVE-2011-1482
Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hija…
Php Nuke
after 8.0
MEDIUM 6.8
CVE-2011-0629
Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to hijack the authentication o…
Coldfusion
Patch available
MEDIUM 6.8
CVE-2011-1954
Multiple cross-site request forgery (CSRF) vulnerabilities in Post Revolution 0.8.0c-2 and earlier allow remote attackers to hijack the authenticatio…
Post Revolution
after 0.8.0c-2
MEDIUM 6.8
CVE-2011-1026
Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hij…
Archiva
No fix yet
MEDIUM 6.8
CVE-2011-1403
Cross-site request forgery (CSRF) vulnerability in the pieforms implementation in Mahara before 1.3.6 allows remote attackers to hijack the authentic…
Mahara
after 1.3.5
MEDIUM 5.8
CVE-2011-1325
Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims …
Ec Cube
after 2.11.0