Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Windows Server 2016 MEDIUM 6.5
CVE-2025-21193

Active Directory Federation Server Spoofing Vulnerability

Fix: 10.0.14393.7699 / 10.0.17763.6775+
Fix from $1,600 2025-01-14
Clarity MEDIUM 6.1
CVE-2024-0590

The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to mi…

Fix: 0.9.4+
Fix from $1,600 2024-02-29
Azure Active Directory MEDIUM 6.8
CVE-2024-21381

Microsoft Azure Active Directory B2C Spoofing Vulnerability

Patch available
Fix from $1,600 2024-02-13
Dynamics 365 MEDIUM 5.4
CVE-2023-24920

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Fix: 9.0.45.11 / 9.1.16.20+
Fix from $1,600 2023-03-14
Power Bi Report Server HIGH 7.6
CVE-2021-41372

A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing H…

Patch available
Fix from $1,950 2021-11-10
Sharepoint Enterprise Server MEDIUM 6.5
CVE-2020-1103

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site…

Patch available
Fix from $1,600 2020-05-21
Sharepoint Foundation HIGH 8.8
CVE-2019-1259

A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site reques…

Patch available
Fix from $1,950 2019-09-11
Sharepoint Enterprise Server HIGH 8.8
CVE-2019-1261

A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site reques…

Patch available
Fix from $1,950 2019-09-11
Azure Devops Server MEDIUM 6.5
CVE-2019-0996

A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site reque…

Patch available
Fix from $1,600 2019-06-12
Asp.net Core MEDIUM 6.5
CVE-2018-0785

ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Si…

Patch available
Fix from $1,600 2018-01-10
Project Server HIGH 8.8
CVE-2017-11876

Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are no…

Patch available
Fix from $1,950 2017-11-15
Exchange Server MEDIUM 6.8
CVE-2015-1771EPSS 6%

Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote a…

Mitigation only
Fix from $1,600 2015-06-10
Outlook Web Access MEDIUM 6.8
CVE-2010-3213EPSS 8%

Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the a…

No fix yet
Fix from $1,600 2010-09-07