Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,432 CVEs tagged with CWE-352140 Critical, 3,377 High, 5,723 Medium, 183 Low, 9 Unrated.

CVE-2016-2884

Published Nov 30, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configuration, allows remote authenti…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3009

Published Nov 30, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authenticat…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-3004

Published Nov 30, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authenticat…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2963

Published Nov 30, 2016

Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8673

Published Nov 23, 2016

A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All ver…

CVSS 8.8 · High

CVE-2016-6444

Published Oct 27, 2016

A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a Web Bridge user. More Infor…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6442

Published Oct 27, 2016

A vulnerability in Cisco Finesse Agent and Supervisor Desktop Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack agains…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8504

Published Oct 26, 2016

CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6417

Published Oct 5, 2016

Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3007

Published Sep 26, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authenti…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4845

Published Sep 24, 2016

Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0…

CVSS 8.8 · High

CVE-2016-6801

Published Sep 21, 2016

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6642

Published Sep 18, 2016

Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authentication of administrators for requests that upload files.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7034

Published Sep 7, 2016

The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7123

Published Sep 2, 2016

Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6893

Published Sep 2, 2016

Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2998

Published Sep 1, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-4069

Published Aug 25, 2016

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachme…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 8,226-8,250 of 9,432 CVEsPage 330 of 378