Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Github Pull Request Builder HIGH 8.8
CVE-2023-24434

A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers to connect to an …

Fix: after 1.42.2
Fix from $1,950 2023-01-26
Jira Pipeline Steps HIGH 8.8
CVE-2023-24437

A cross-site request forgery (CSRF) vulnerability in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers to connect…

Fix: after 2.0.165.v8846cf59f3db
Fix from $1,950 2023-01-26
Gerrit Trigger MEDIUM 6.5
CVE-2023-24423

A cross-site request forgery (CSRF) vulnerability in Jenkins Gerrit Trigger Plugin 2.38.0 and earlier allows attackers to rebuild previous builds tri…

Fix: 2.38.1+
Fix from $1,600 2023-01-26
Application Delivery Controller HIGH 8.8
CVE-2022-37719

A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbi…

No fix yet
Fix from $1,950 2023-01-23
Optimize Images Alt Text \(alt Tag\) \& Names For Seo Using Ai MEDIUM 6.5
CVE-2022-4548

The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place when updating its settings, whi…

Fix: 2.0.8+
Fix from $1,600 2023-01-23
Modoboa MEDIUM 6.5
CVE-2023-0438

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.

Fix: 2.0.4+
Fix from $1,600 2023-01-23
Social Warfare MEDIUM 5.4
CVE-2023-0403

The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing o…

Fix: 4.4.0+
Fix from $1,600 2023-01-19
Modoboa MEDIUM 6.5
CVE-2023-0398

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.

Fix: 2.0.4+
Fix from $1,600 2023-01-19
Real Time Location System Studio HIGH 8.1
CVE-2022-45127

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its ba…

Fix: after 2.6.2
Fix from $1,950 2023-01-18
Real Time Location System Studio HIGH 8.1
CVE-2022-47395

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its mo…

Fix: after 2.6.2
Fix from $1,950 2023-01-18
Vcc Hd5600p Firmware HIGH 8.8
CVE-2022-4621

Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are vulnerable to CSRFs that can be exploited to allow an attacker to perform cha…

Mitigation only
Fix from $1,950 2023-01-17
Maho Pbx Netdevancer Firmware HIGH 8.1
CVE-2023-22286

Cross-site request forgery (CSRF) vulnerability in MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni pr…

Fix: 1.11.00+
Fix from $1,950 2023-01-17
Openstreetmap HIGH 8.8
CVE-2022-30544

Cross-Site Request Forgery (CSRF) in MiKa's OSM – OpenStreetMap plugin <= 6.0.1 versions.

Fix: after 6.0.1
Fix from $1,950 2023-01-17
Superset HIGH 8.8
CVE-2022-43719

Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset versio…

Fix: after 1.5.2
Fix from $1,950 2023-01-16
Tiki MEDIUM 6.5
CVE-2023-22852

Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.

Fix: after 25.0
Fix from $1,600 2023-01-14
Rumpus HIGH 8.8
CVE-2022-46367

Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.

Fix: after 9.0.7.1
Fix from $1,950 2023-01-12
Rumpus HIGH 8.8
CVE-2022-46368

Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.

Fix: after 9.0.7.1
Fix from $1,950 2023-01-12
Royal Elementor Addons MEDIUM 6.5
CVE-2022-4707

The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.59. This is due to …

Fix: after 1.3.59
Fix from $1,600 2023-01-10
Desktop HIGH 8.8
CVE-2023-22472

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. It is possible to m…

Patch available
Fix from $1,950 2023-01-09
Swifty Page Manager HIGH 8.8
CVE-2023-0088

The Swifty Page Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.1. This is due to miss…

Fix: after 3.0.1
Fix from $1,950 2023-01-05
Jetwidgets For Elementor MEDIUM 6.5
CVE-2023-0086

The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.12. This is due t…

Fix: after 1.0.12
Fix from $1,600 2023-01-05
Bug Tracker HIGH 8.8
CVE-2016-15009

A vulnerability classified as problematic has been found in OpenACS bug-tracker. Affected is an unknown function of the file lib/nav-bar.adp of the c…

Fix: 2016-05-25+
Fix from $1,950 2023-01-05
Ckeditor Integration HIGH 8.8
CVE-2023-22457EPSS 19%

CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a …

Fix: 1.64.3+
Fix from $1,950 2023-01-04
Business Automation Workflow HIGH 8.8
CVE-2022-42435

IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.1 is vulner…

Patch available
Fix from $1,950 2023-01-04
Iubenda Cookie Law Solution HIGH 8.8
CVE-2022-3911

The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be upd…

Fix: 3.3.3+
Fix from $1,950 2023-01-02
Idp Test Clients HIGH 8.8
CVE-2014-125028

A vulnerability was found in valtech IDP Test Client and classified as problematic. Affected by this issue is some unknown functionality of the file …

Fix: 2014-09-25+
Fix from $1,950 2022-12-31
Memos HIGH 8.8
CVE-2022-4844

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,950 2022-12-29
Memos MEDIUM 6.5
CVE-2022-4846

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-29
Memos MEDIUM 6.5
CVE-2022-4849

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-29
Memos MEDIUM 6.5
CVE-2022-4850

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-29