Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,429 CVEs tagged with CWE-352140 Critical, 3,377 High, 5,723 Medium, 183 Low, 6 Unrated.

CVE-2016-5937

Published Feb 1, 2017

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3029

Published Feb 1, 2017

IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user…

CVSS 8.8 · High

CVE-2017-3794

Published Jan 26, 2017

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9218

Published Jan 26, 2017

A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against the user of the web in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6521

Published Jan 23, 2017

Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows remote attackers to hijack th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3406

Published Jan 18, 2017

Multiple cross-site request forgery (CSRF) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to hijack the authentication of unspecified victims via vect…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6897

Published Jan 18, 2017

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hija…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7980

Published Jan 18, 2017

Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7904

Published Jan 16, 2017

Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrators for requests that create acc…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5492

Published Jan 15, 2017

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5489

Published Jan 15, 2017

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8201

Published Jan 14, 2017

A CSRF vulnerability in Brocade Virtual Traffic Manager versions released prior to and including 11.0 could allow an attacker to trick a logged-in user into making administrative…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5476

Published Jan 14, 2017

Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5475

Published Jan 14, 2017

comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5473

Published Jan 14, 2017

Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lu…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4808

Published Jan 11, 2017

Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4593

Published Jan 10, 2017

eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authent…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7885

Published Dec 15, 2016

Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6468

Published Dec 14, 2016

A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9866

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-2884

Published Nov 30, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configuration, allows remote authenti…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3009

Published Nov 30, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authenticat…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 8,201-8,225 of 9,429 CVEsPage 329 of 378