Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Wallabag MEDIUM 6.5
CVE-2023-4455

Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

Fix: 2.6.3+
Fix from $1,600 2023-08-21
Wallabag MEDIUM 5.7
CVE-2023-4454

Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

Fix: 2.6.3+
Fix from $1,600 2023-08-21
Social Media Skeleton HIGH 8.8
CVE-2023-40172

Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. A Cross-site request forger…

Fix: 1.0.5+
Fix from $1,950 2023-08-18
Wolf Wordpress Posts Bulk Editor And Products Manager Professional MEDIUM 6.1
CVE-2023-31218

Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Man…

Fix: 1.0.7+
Fix from $1,600 2023-08-18
Video Phone 8875 Firmware MEDIUM 6.5
CVE-2023-20221

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauth…

Fix: 2.0+
Fix from $1,600 2023-08-16
Folders HIGH 8.8
CVE-2023-40336

A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy folders.

Fix: after 6.846.v23698686f0f6
Fix from $1,950 2023-08-16
Blue Ocean HIGH 8.8
CVE-2023-40341

A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specifie…

Fix: after 1.27.5
Fix from $1,950 2023-08-16
Yzmcms HIGH 8.8
CVE-2020-23595

Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information …

No fix yet
Fix from $1,950 2023-08-11
Xxl Job HIGH 8.8
CVE-2020-24922

Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitr…

No fix yet
Fix from $1,950 2023-08-11
Absolute Privacy HIGH 8.8
CVE-2023-4276

The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing n…

Fix: after 2.1
Fix from $1,950 2023-08-10
Realia MEDIUM 6.5
CVE-2023-4277

The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce val…

Fix: after 1.4.0
Fix from $1,600 2023-08-10
Benno Mailarchiv HIGH 8.8
CVE-2023-38348

A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1.

Fix: 2.10.2+
Fix from $1,950 2023-08-09
Opnsense MEDIUM 6.5
CVE-2023-38999

A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.…

Fix: 23.7+
Fix from $1,600 2023-08-09
Prtg Network Monitor HIGH 8.8
CVE-2023-31452

A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform act…

Fix: 23.3.86.1520+
Fix from $1,950 2023-08-09
Workout Manager HIGH 8.8
CVE-2023-38759

Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user…

Mitigation only
Fix from $1,950 2023-08-08
Firefox HIGH 8.8
CVE-2023-4047

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerabil…

Fix: 102.14 / 115.1+
Fix from $1,950 2023-08-01
Zlt S10g Firmware HIGH 8.8
CVE-2023-33534

A Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11.6 allows attackers to takeove…

No fix yet
Fix from $1,950 2023-07-31
Duxcms MEDIUM 6.5
CVE-2020-21881

Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via article/admin/cont…

No fix yet
Fix from $1,600 2023-07-31
Wpstream HIGH 8.8
CVE-2023-38512

Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream wpstream allows Cross Site Request Forgery.This issue affects WpStream: from n/a…

Fix: 4.5.5+
Fix from $1,950 2023-07-27
Servicenow Devops MEDIUM 6.5
CVE-2023-3414

A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited success…

Fix: 1.38.1+
Fix from $1,600 2023-07-26
Gitlab Authentication MEDIUM 5.4
CVE-2023-39153

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into log…

Fix: after 1.17.1
Fix from $1,600 2023-07-26
Bazaar MEDIUM 5.3
CVE-2023-39156

A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete previously created Bazaar SCM …

Fix: after 1.22
Fix from $1,600 2023-07-26
Xperiencentral HIGH 8.8
CVE-2022-43710

Interactive Forms (IAF) in GX Software XperienCentral versions 10.31.0 until 10.33.0 was vulnerable to cross site request forgery (CSRF) because the …

Fix: after 10.33.0
Fix from $1,950 2023-07-26
Netact HIGH 8.8
CVE-2022-30280

/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even adm…

No fix yet
Fix from $1,950 2023-07-24
Nxfilter HIGH 8.8
CVE-2023-3841

A vulnerability has been found in NxFilter 4.3.2.5 and classified as problematic. This vulnerability affects unknown code of the file user.jsp. The m…

Mitigation only
Fix from $1,950 2023-07-23
Cockpit HIGH 8.8
CVE-2023-37650

A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.

Fix: after 2.5.2
Fix from $1,950 2023-07-20
Bigfix Webui MEDIUM 6.5
CVE-2023-28023

A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to a…

Fix: after 44
Fix from $1,600 2023-07-18
Media Library Helper HIGH 8.8
CVE-2023-37386

Cross-Site Request Forgery (CSRF) vulnerability in Media Library Helper plugin <= 1.2.0 versions.

Fix: after 1.2.0
Fix from $1,950 2023-07-18
Classified Listing HIGH 8.8
CVE-2023-37387

Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions.

Fix: after 2.4.5
Fix from $1,950 2023-07-18
Aws Cdn HIGH 8.8
CVE-2023-37889

Cross-Site Request Forgery (CSRF) vulnerability in WPAdmin WPAdmin AWS CDN plugin <= 2.0.13 versions.

Fix: after 2.0.13
Fix from $1,950 2023-07-18