Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2008-0788 Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of mode… Mybb after 1.2.11 Fix from $1,6002008-02-15 MEDIUM 6.8 CVE-2008-0508 Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows … Permalinks Migration Plugin Patch available Fix from $1,6002008-01-31 HIGH 7.5 CVE-2008-0524 Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change pa… Rt107e Mitigation only Fix from $1,9502008-01-31 HIGH 9.3 CVE-2008-0228 Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote at… Wrt54gl Mitigation only Fix from $1,9502008-01-10 MEDIUM 6.8 CVE-2007-6642 Multiple cross-site request forgery (CSRF) vulnerabilities in Joomla! before 1.5 RC4 allow remote attackers to (1) add a Super Admin, (2) upload an e… Joomla Mitigation only Fix from $1,6002008-01-04 MEDIUM 5.0 CVE-2007-6300 Cross-site request forgery (CSRF) vulnerability in Fusion News 3.9.0 allows remote attackers to perform unauthorized actions via unspecified vectors. Fusion News Mitigation only Fix from $1,6002007-12-10 MEDIUM 6.8 CVE-2007-6087 Cross-site request forgery (CSRF) vulnerability in index.php in VigileCMS 1.4 allows remote attackers to change the admin password via certain parame… Vigilecms No fix yet Fix from $1,6002007-11-22 MEDIUM 6.8 CVE-2007-5917 Cross-site request forgery (CSRF) vulnerability in admin/admin_account.php in Skalinks 1.5 and earlier allows remote attackers to add arbitrary privi… Skalinks Mitigation only Fix from $1,6002007-11-10 MEDIUM 6.0 CVE-2007-5918 Cross-site request forgery (CSRF) vulnerability in edit.php in the MS TopSites add-on for PHP-Nuke does not verify that the uname parameter matches t… Ms Topsites Mitigation only Fix from $1,6002007-11-10 MEDIUM 6.8 CVE-2007-5828 Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via … Django Mitigation only Fix from $1,6002007-11-05 HIGH 7.6 CVE-2007-5818 Cross-site request forgery (CSRF) vulnerability in blocks_edit_do.php in sBlog 0.7.3 Beta allows remote attackers to change arbitrary blocks as admin… Sblog Mitigation only Fix from $1,9502007-11-05 MEDIUM 6.4 CVE-2007-5229 Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and h… Feedsmith Patch available Fix from $1,6002007-10-05 HIGH 9.3 CVE-2007-5213 Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers… 2100 Network Camera after 2.42 Fix from $1,9502007-10-04 MEDIUM 5.1 CVE-2007-5032 Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via a… Php Nuke after 5.2 Fix from $1,6002007-09-21 MEDIUM 5.0 CVE-2007-3416 Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans, and (4) forums in (a) web-a… Webapp after 0.9.9.6 Fix from $1,6002007-06-26 MEDIUM 5.0 CVE-2007-2589 Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attackers to send e-mails from arbi… Squirrelmail Patch available Fix from $1,6002007-05-11 MEDIUM 6.8 CVE-2007-1520 The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the… Php Nuke after 8.0 Fix from $1,6002007-03-20 MEDIUM 6.8 CVE-2007-1489 Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modi… Webapp Patch available Fix from $1,6002007-03-16 HIGH 7.6 CVE-2007-1157 Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administ… Jboss Mitigation only Fix from $1,9502007-03-02 MEDIUM 5.8 CVE-2006-6741 Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a… Mkportal Mitigation only Fix from $1,6002006-12-26 HIGH 7.5 CVE-2006-6701 Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify … Atmail Webmail Mitigation only Fix from $1,9502006-12-23 HIGH 7.6 CVE-2006-5175 Cross-site request forgery (CSRF) vulnerability in the administrative interface for the TeraStation HD-HTGL firmware 2.05 beta 1 and earlier allows r… Terastation Hd Htgl Firmware 2.08+ Fix from $1,9502006-10-10 MEDIUM 6.5 CVE-2005-2059 Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.p… Ubb.threads after 6.5.1.1 Fix from $1,6002005-06-29 MEDIUM 6.5 CVE-2005-1674 Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG… Help Center Live Patch available Fix from $1,6002005-05-19 HIGH 8.8 CVE-2004-1842 Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img ta… Php Nuke after 7.1 Fix from $1,9502004-12-31 MEDIUM 6.5 CVE-2004-1995 Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm. Fusetalk No fix yet Fix from $1,6002004-12-31 HIGH 8.8 CVE-2004-1703 Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that… Fusion News No fix yet Fix from $1,9502004-07-30 HIGH 8.8 CVE-2004-1967 Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6)… Openbb No fix yet Fix from $1,9502004-04-25