Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Sales Tracker Management System HIGH 8.8
CVE-2023-0999

A vulnerability classified as problematic was found in SourceCodester Sales Tracker Management System 1.0. This vulnerability affects unknown code of…

No fix yet
Fix from $1,950 2023-02-24
Infinity Dc Power Plant HIGH 8.8
CVE-2022-1607

Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request F…

Fix: 5.0.0+
Fix from $1,950 2023-02-24
Application Policy Infrastructure Controller HIGH 8.8
CVE-2023-20011

A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller…

Fix: 5.2 / 6.0+
Fix from $1,950 2023-02-23
Online Pizza Ordering System HIGH 8.8
CVE-2023-0988

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Pizza Ordering System 1.0. This issue affects some unkn…

No fix yet
Fix from $1,950 2023-02-23
Chatbot HIGH 8.8
CVE-2023-24415

Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions.

Fix: 4.2.9+
Fix from $1,950 2023-02-23
Motomo HIGH 8.8
CVE-2023-23659

Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions.

Fix: 4.0.5+
Fix from $1,950 2023-02-23
Organization Chart HIGH 8.8
CVE-2023-24384

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.

Fix: after 1.4.4
Fix from $1,950 2023-02-23
Submitbymailplugin HIGH 8.8
CVE-2015-10081

A vulnerability was found in arnoldle submitByMailPlugin 1.0b2.9 and classified as problematic. This issue affects some unknown processing of the fil…

Patch available
Fix from $1,950 2023-02-20
Apollo MEDIUM 5.7
CVE-2023-25569

Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal …

Fix: 2.1.0+
Fix from $1,600 2023-02-20
Booking Calendar MEDIUM 5.4
CVE-2023-24388

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin form…

Fix: 3.2.4+
Fix from $1,600 2023-02-17
Baijiacms MEDIUM 6.5
CVE-2021-33396

Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary acco…

No fix yet
Fix from $1,600 2023-02-15
Media Control Panel HIGH 8.8
CVE-2023-23465

Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.

No fix yet
Fix from $1,950 2023-02-15
Azure Credentials HIGH 8.8
CVE-2023-25767

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an…

Fix: 254.v64da_8176c83a+
Fix from $1,950 2023-02-15
Pandora Fms MEDIUM 6.1
CVE-2022-47373

Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forg…

Fix: after 766
Fix from $1,600 2023-02-15
Pandora Fms MEDIUM 5.4
CVE-2022-47372

Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vuln…

Fix: after 766
Fix from $1,600 2023-02-15
Firco Compliance Link HIGH 8.8
CVE-2022-29557

LexisNexis Firco Compliance Link 3.7 allows CSRF.

Mitigation only
Fix from $1,950 2023-02-15
Quiz And Survey Master HIGH 8.8
CVE-2022-46862

Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0…

Fix: 8.0.8+
Fix from $1,950 2023-02-14
Ecwid Ecommerce Shopping Cart HIGH 8.8
CVE-2023-24377

Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions.

Fix: 6.11.4+
Fix from $1,950 2023-02-14
Material Design Icons For Page Builders HIGH 8.8
CVE-2023-24382

Cross-Site Request Forgery (CSRF) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions.

Fix: 1.4.3+
Fix from $1,950 2023-02-14
Wp Tabs HIGH 8.8
CVE-2023-25065

Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <= 2.1.14 versions.

Fix: 2.1.15+
Fix from $1,950 2023-02-14
Corona Virus \(covid 19\) Banner \& Live Data HIGH 8.8
CVE-2022-43469

Cross-Site Request Forgery (CSRF) vulnerability in Orchestrated Corona Virus (COVID-19) Banner & Live Data plugin <= 1.7.0.6 versions.

Fix: after 1.7.0.6
Fix from $1,950 2023-02-14
Fv Flowplayer Video Player HIGH 8.8
CVE-2023-25066

Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions.

Fix: after 7.5.30.7212
Fix from $1,950 2023-02-14
Cs Wmv02g Firmware HIGH 8.8
CVE-2023-22375

Cross-site request forgery (CSRF) vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a remote unauthenticated …

Mitigation only
Fix from $1,950 2023-02-14
GitLab HIGH 8.1
CVE-2022-4138

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 1…

Fix: 15.6.7 / 15.7.6+
Fix from $1,950 2023-02-13
Optinly HIGH 8.8
CVE-2022-41134

Cross-Site Request Forgery (CSRF) in OptinlyHQ Optinly – Exit Intent, Newsletter Popups, Gamification & Opt-in Forms plugin <= 1.0.15 versions.

Fix: 1.0.16+
Fix from $1,950 2023-02-13
Powerpath Management Appliance HIGH 8.8
CVE-2022-34448

PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Cross-site Request Forgery vulnerability. An unauthenticated non-privi…

Mitigation only
Fix from $1,950 2023-02-11
Imagemagick Engine HIGH 8.8
CVE-2022-3568

The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and i…

Fix: 1.7.6+
Fix from $1,950 2023-02-10
Seosamba HIGH 8.8
CVE-2022-41620

Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions.

Fix: after 1.0.5
Fix from $1,950 2023-02-08
Wallabag MEDIUM 6.5
CVE-2023-0735

Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.

Fix: 2.5.4+
Fix from $1,600 2023-02-07
0mk Shortener MEDIUM 5.4
CVE-2022-2933

The 0mk Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing or i…

Fix: after 0.2
Fix from $1,600 2023-02-06