Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2009-4407 Multiple cross-site request forgery (CSRF) vulnerabilities in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attacker… Pyforum after 1.0.3 Fix from $1,6002009-12-23 MEDIUM 6.8 CVE-2009-3580 Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrary users… Sql Ledger Mitigation only Fix from $1,6002009-12-23 MEDIUM 6.8 CVE-2009-4385 Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the authenticat… Ez Poll Hoster No fix yet Fix from $1,6002009-12-22 MEDIUM 6.8 CVE-2009-4349 Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote attackers to hijack the authen… Link Up Gold No fix yet Fix from $1,6002009-12-17 MEDIUM 6.8 CVE-2009-4297 Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the auth… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 6.8 CVE-2009-4173 Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authenti… Cutenews No fix yet Fix from $1,6002009-12-02 MEDIUM 6.8 CVE-2009-4120 Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator… Quick.cart No fix yet Fix from $1,6002009-12-01 MEDIUM 6.8 CVE-2009-4121 Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attackers to hijack the authenticatio… Quick.cms No fix yet Fix from $1,6002009-12-01 MEDIUM 6.8 CVE-2009-4092EPSS 5% Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentic… Simplog No fix yet Fix from $1,6002009-11-29 MEDIUM 6.8 CVE-2009-4076 Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspec… Webmail after 0.2.2 Fix from $1,6002009-11-25 MEDIUM 6.8 CVE-2009-4077 Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspec… Webmail after 0.2.2 Fix from $1,6002009-11-25 MEDIUM 6.8 CVE-2009-4079 Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users for reques… Redmine after 0.8.5 Fix from $1,6002009-11-25 MEDIUM 6.8 CVE-2009-4066 Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.… Drupal Patch available Fix from $1,6002009-11-24 MEDIUM 6.8 CVE-2009-2746 Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0… Websphere Application Server Patch available Fix from $1,6002009-11-16 MEDIUM 6.8 CVE-2009-2816 The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, inclu… Safari 3.0.195.33 / 4.0+ Fix from $1,6002009-11-13 MEDIUM 6.8 CVE-2009-3922 Multiple cross-site request forgery (CSRF) vulnerabilities in the User Protect module 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal,… Userprotect Patch available Fix from $1,6002009-11-09 MEDIUM 6.8 CVE-2009-3784 Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary … Simplenews Statistics Patch available Fix from $1,6002009-10-26 MEDIUM 6.8 CVE-2009-3785 Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers t… Simplenews Statistics Patch available Fix from $1,6002009-10-26 HIGH 8.8 CVE-2009-3759 Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers… Xencenterweb No fix yet Fix from $1,9502009-10-22 MEDIUM 6.8 CVE-2009-3656 Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authenticat… Shared Sign On Mitigation only Fix from $1,6002009-10-09 HIGH 8.8 CVE-2009-3520 Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of adm… Cmsphp No fix yet Fix from $1,9502009-10-01 MEDIUM 6.8 CVE-2009-3248 Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin u… Vtiger Crm No fix yet Fix from $1,6002009-09-18 MEDIUM 6.8 CVE-2008-7241 Cross-site request forgery (CSRF) vulnerability in PunBB before 1.2.17 allows remote attackers to hijack the authentication of unspecified users for … Punbb after 1.2.16 Fix from $1,6002009-09-17 MEDIUM 6.8 CVE-2008-7243 Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of … Modxcms No fix yet Fix from $1,6002009-09-17 MEDIUM 6.8 CVE-2008-7221 Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for requests t… Runcms Mitigation only Fix from $1,6002009-09-14 MEDIUM 6.8 CVE-2008-7204 Cross-site request forgery (CSRF) vulnerability in VirtueMart 1.0.13a and earlier allows remote attackers to hijack the authentication of administrat… Virtuemart after 1.0.13 Fix from $1,6002009-09-11 MEDIUM 6.8 CVE-2008-7214 Cross-site request forgery (CSRF) vulnerability in administrator/index2.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote… Mambo after 4.6.3 Fix from $1,6002009-09-11 HIGH 9.3 CVE-2007-6730 Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in the ZyXEL P-330W router allow remote attackers to hijac… P 330w Router No fix yet Fix from $1,9502009-09-10 MEDIUM 6.8 CVE-2008-7192 Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote att… Burning Board Mitigation only Fix from $1,6002009-09-09 MEDIUM 6.8 CVE-2008-7193 PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by reading th… Phpkit Mitigation only Fix from $1,6002009-09-09