Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2017-12-14 CVE-2017-5264 Cross-Site Request Forgery (CSRF) vulnerability in Rapid7 Nexpose
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.
network
low complexity
rapid7 CWE-352
8.8
2017-12-13 CVE-2017-14362 Cross-Site Request Forgery (CSRF) vulnerability in Microfocus Project and Portfolio Management 9.32
Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32.
network
low complexity
microfocus CWE-352
7.3
2017-12-04 CVE-2017-17056 Cross-Site Request Forgery (CSRF) vulnerability in Zkteco Zktime web 2.0.1.12280
The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password component, reachable via the old_password, new_password1, and new_password2 parameters to the /accounts/password_change/ URI.
network
low complexity
zkteco CWE-352
8.8
2017-11-30 CVE-2017-12631 Cross-Site Request Forgery (CSRF) vulnerability in Apache CXF Fediz
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications.
network
low complexity
apache CWE-352
8.8
2017-11-28 CVE-2016-10701 Cross-Site Request Forgery (CSRF) vulnerability in Hitachivantara Pentaho Business Analytics 8.0
In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application.
network
low complexity
hitachivantara CWE-352
8.8
2017-11-22 CVE-2017-8138 Cross-Site Request Forgery (CSRF) vulnerability in Huawei Hedex Lite
HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability.
network
low complexity
huawei CWE-352
8.8
2017-11-17 CVE-2017-1000224 Cross-Site Request Forgery (CSRF) vulnerability in Embedplus Youtube
CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin
network
low complexity
embedplus CWE-352
6.5
2017-11-16 CVE-2017-15516 Cross-Site Request Forgery (CSRF) vulnerability in Netapp Snapcenter Server 1.1/2.0
NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause an unintended authenticated action in the user interface.
network
low complexity
netapp CWE-352
8.8
2017-11-15 CVE-2017-7851 Cross-Site Request Forgery (CSRF) vulnerability in D-Link Dcs-936L
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.
network
low complexity
d-link CWE-352
8.8
2017-11-15 CVE-2017-11876 Cross-Site Request Forgery (CSRF) vulnerability in Microsoft Project Server and Sharepoint Enterprise Server
Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, such as change permissions and delete content, and inject malicious content in the browser of the victim, aka "Microsoft Project Server Elevation of Privilege Vulnerability".
network
low complexity
microsoft CWE-352
8.8