Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Acera 1210 Firmware HIGH 8.8
CVE-2023-41086

Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while lo…

Fix: after 02.36
Fix from $1,950 2023-10-03
Free5gc CRITICAL 9.8
CVE-2023-4659

Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator…

Mitigation only
Fix from $2,300 2023-10-02
Ajaxnewsticker HIGH 8.8
CVE-2023-41452

Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to…

Mitigation only
Fix from $1,950 2023-09-27
Cyber Protect MEDIUM 6.5
CVE-2023-44160

Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) …

Fix: 15+
Fix from $1,600 2023-09-27
Cyber Protect MEDIUM 6.5
CVE-2023-44161

Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) …

Fix: 15+
Fix from $1,600 2023-09-27
Ws Ftp Server MEDIUM 6.5
CVE-2023-40048

In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST tra…

Fix: 8.8.2+
Fix from $1,600 2023-09-27
Access Controller HIGH 8.8
CVE-2023-35793

An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request …

No fix yet
Fix from $1,950 2023-09-27
Seacms HIGH 8.8
CVE-2023-43278

A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.

Fix: after 12.8
Fix from $1,950 2023-09-25
Icms HIGH 8.8
CVE-2023-42321

Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, …

Mitigation only
Fix from $1,950 2023-09-20
Build Failure Analyzer HIGH 8.8
CVE-2023-43500

A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attack…

Fix: 2.4.2+
Fix from $1,950 2023-09-20
Mobility Print Server MEDIUM 6.5
CVE-2023-2508

The `PaperCutNG Mobility Print` version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attack on an instance administrat…

No fix yet
Fix from $1,600 2023-09-20
Ekorrci Firmware HIGH 8.8
CVE-2022-47559

Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when…

Mitigation only
Fix from $1,950 2023-09-19
Modulys Gp Firmware HIGH 8.8
CVE-2023-39446

Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is…

No fix yet
Fix from $1,950 2023-09-18
Memos HIGH 8.8
CVE-2023-5036

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

Fix: 0.15.1+
Fix from $1,950 2023-09-18
Grocy HIGH 8.8
CVE-2023-42270

Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).

Fix: after 4.0.2
Fix from $1,950 2023-09-15
Quay MEDIUM 6.5
CVE-2023-4959

A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, i…

Mitigation only
Fix from $1,600 2023-09-15
Moosocial HIGH 8.8
CVE-2023-40868

Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbitrary code via the Delete Acc…

No fix yet
Fix from $1,950 2023-09-14
Login With Phone Number HIGH 8.8
CVE-2023-4916

The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to …

Fix: after 1.5.6
Fix from $1,950 2023-09-13
Contact Manager App HIGH 8.8
CVE-2023-4869

A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been rated as problematic. Affected by this issue is some unknown functio…

No fix yet
Fix from $1,950 2023-09-10
Contact Manager App HIGH 8.8
CVE-2023-4868

A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been declared as problematic. Affected by this vulnerability is an unknow…

No fix yet
Fix from $1,950 2023-09-10
Take Note App HIGH 8.8
CVE-2023-4865

A vulnerability has been found in SourceCodester Take-Note App 1.0 and classified as problematic. This vulnerability affects unknown code. The manipu…

No fix yet
Fix from $1,950 2023-09-09
Icms HIGH 8.8
CVE-2023-40953

icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).

Mitigation only
Fix from $1,950 2023-09-08
Ivy MEDIUM 6.5
CVE-2023-41938

A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and earlier allows attackers to delete disabled modules.

Fix: after 2.5
Fix from $1,600 2023-09-06
Airwave HIGH 8.8
CVE-2015-1391

Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.

Fix: 8.0.7+
Fix from $1,950 2023-09-05
Softswitch HIGH 8.8
CVE-2023-39372

StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352)

Mitigation only
Fix from $1,950 2023-09-03
Sel 5037 Sel Grid Configurator MEDIUM 6.5
CVE-2023-31174

A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker t…

Fix: 4.5.0.20+
Fix from $1,600 2023-08-31
Wp Directory Kit MEDIUM 5.4
CVE-2023-2279

The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing…

Fix: 1.2.2+
Fix from $1,600 2023-08-31
Infosphere Information Server HIGH 8.8
CVE-2023-23473

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-08-28
Xwiki HIGH 8.0
CVE-2023-40572

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF at…

Fix: 14.10.9+
Fix from $1,950 2023-08-24
Fortify MEDIUM 5.4
CVE-2023-4301

A cross-site request forgery (CSRF) vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers to connect to an attacker-specified …

Fix: 22.2.39+
Fix from $1,600 2023-08-21