Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2012-0286 Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspec… Webnetwork after 6.0.7.0 Fix from $1,6002012-01-24 MEDIUM 6.8 CVE-2011-3668 Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the aut… Bugzilla No fix yet Fix from $1,6002012-01-02 MEDIUM 6.8 CVE-2011-3669 Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the a… Bugzilla No fix yet Fix from $1,6002012-01-02 MEDIUM 6.8 CVE-2011-5011 Multiple cross-site request forgery (CSRF) vulnerabilities in xt:Commerce 3.0.4 SP2.1 and possibly earlier allow remote attackers to hijack the authe… Xt Commerce Mitigation only Fix from $1,6002011-12-25 MEDIUM 6.8 CVE-2011-3836 Multiple cross-site request forgery (CSRF) vulnerabilities in Wuzly 2.0 allow remote attackers to hijack the authentication of administrators for req… Wuzly Mitigation only Fix from $1,6002011-12-24 MEDIUM 6.8 CVE-2011-4837 Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authenti… Homeseer Hs2 Mitigation only Fix from $1,6002011-12-15 MEDIUM 6.8 CVE-2011-3636 Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authenticat… Freeipa after 2.1.3 Fix from $1,6002011-12-08 MEDIUM 6.8 CVE-2011-4498 Cross-site request forgery (CSRF) vulnerability in the web console in Zenprise Device Manager 6.x through 6.1.8 allows remote attackers to hijack the… Zenprise Device Manager Patch available Fix from $1,6002011-11-21 MEDIUM 6.8 CVE-2011-2773 Cross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1 allows remote attackers to hijack the authentication of administrators for req… Mahara after 1.4.0 Fix from $1,6002011-11-15 MEDIUM 6.8 CVE-2011-3994 Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earl… Autotagging after 5.251 Fix from $1,6002011-11-03 HIGH 9.3 CVE-2011-4005 Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521… Small Business Srp521w after 1.02.01_mr2 Fix from $1,9502011-11-03 MEDIUM 6.8 CVE-2011-1364 Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console)… App Engine Python Sdk after 1.5.3 Fix from $1,6002011-10-30 MEDIUM 6.8 CVE-2011-4173 Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authentication … Smf Mitigation only Fix from $1,6002011-10-24 MEDIUM 6.8 CVE-2011-4140 The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary… Django after 1.2.6 Fix from $1,6002011-10-19 MEDIUM 6.8 CVE-2010-4881 Multiple cross-site request forgery (CSRF) vulnerabilities in calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote attackers to hijack the a… Apphp Calendar No fix yet Fix from $1,6002011-10-07 MEDIUM 6.8 CVE-2011-2191 Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of a… Cherokee after 1.2.98 Fix from $1,6002011-10-07 MEDIUM 6.8 CVE-2011-1911 JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remo… Jasperreports Server Community Project Mitigation only Fix from $1,6002011-09-20 MEDIUM 6.8 CVE-2011-3381 Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified victims v… Phorum after 5.2.15 Fix from $1,6002011-09-08 MEDIUM 6.8 CVE-2011-1341 Cross-site request forgery (CSRF) vulnerability in Aimluck Aipo before 4.0.4.0, and Aipo for ASP before 4.0.4.0, allows remote attackers to hijack th… Aipo after 4.0.3.0 Fix from $1,6002011-08-19 MEDIUM 6.8 CVE-2011-0551 Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.60… Endpoint Protection Mitigation only Fix from $1,6002011-08-15 MEDIUM 6.8 CVE-2011-2522EPSS 10% Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attack… Debian Linux 3.3.16 / 3.4.14+ Fix from $1,6002011-07-29 MEDIUM 6.8 CVE-2009-4139 A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authent… Network Satellite Server Patch available Fix from $1,6002011-07-27 MEDIUM 6.8 CVE-2010-3271 Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Applicat… Websphere Application Server after 7.0.0.13 Fix from $1,6002011-07-18 MEDIUM 6.8 CVE-2011-2753 Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of … Squirrelmail after 1.4.21 Fix from $1,6002011-07-17 MEDIUM 6.8 CVE-2011-1482 Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hija… Php Nuke after 8.0 Fix from $1,6002011-06-21 MEDIUM 6.8 CVE-2011-0629 Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to hijack the authentication o… Coldfusion Patch available Fix from $1,6002011-06-16 MEDIUM 6.8 CVE-2011-1954 Multiple cross-site request forgery (CSRF) vulnerabilities in Post Revolution 0.8.0c-2 and earlier allow remote attackers to hijack the authenticatio… Post Revolution after 0.8.0c-2 Fix from $1,6002011-06-06 MEDIUM 6.8 CVE-2011-1026 Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hij… Archiva No fix yet Fix from $1,6002011-06-02 MEDIUM 6.8 CVE-2011-1403 Cross-site request forgery (CSRF) vulnerability in the pieforms implementation in Mahara before 1.3.6 allows remote attackers to hijack the authentic… Mahara after 1.3.5 Fix from $1,6002011-05-13 MEDIUM 5.8 CVE-2011-1325 Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims … Ec Cube after 2.11.0 Fix from $1,6002011-05-13