Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Golf HIGH 8.8
CVE-2016-15005

CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values an…

Fix: 0.3.0+
Fix from $1,950 2022-12-27
Dolibarr Project Timesheet MEDIUM 6.5
CVE-2022-4766

A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of …

Fix: 4.5.6+
Fix from $1,600 2022-12-27
Moodle Block Sitenews MEDIUM 6.5
CVE-2020-36633

A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file bloc…

Fix: 1.1+
Fix from $1,600 2022-12-27
Togglz HIGH 8.8
CVE-2020-28191

The console in Togglz before 2.9.4 allows CSRF.

Fix: 2.9.4+
Fix from $1,950 2022-12-26
Nbnbk MEDIUM 6.5
CVE-2022-46491

A Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allows attackers to arbitrarily a…

No fix yet
Fix from $1,600 2022-12-22
Chat HIGH 8.8
CVE-2020-36625

A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocket.Upgrader of the file main.g…

Patch available
Fix from $1,950 2022-12-22
Rdiffweb MEDIUM 6.5
CVE-2022-4646

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4.

Fix: 2.5.4+
Fix from $1,600 2022-12-22
Pyambic Pentameter HIGH 8.8
CVE-2021-4275

A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation lea…

Patch available
Fix from $1,950 2022-12-21
Auto Upload Images HIGH 8.8
CVE-2022-4633

A vulnerability was found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this issue is some unknown functionality of th…

Fix: 3.3.1+
Fix from $1,950 2022-12-21
Phpredisadmin HIGH 8.8
CVE-2021-4268

A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads t…

Fix: 1.18.0+
Fix from $1,950 2022-12-21
Bienlein MEDIUM 6.5
CVE-2020-36622

A vulnerability was found in sah-comp bienlein and classified as problematic. This issue affects some unknown processing. The manipulation leads to c…

Fix: 2020-09-28+
Fix from $1,600 2022-12-21
Pengu MEDIUM 6.5
CVE-2020-36623

A vulnerability was found in Pengu. It has been declared as problematic. Affected by this vulnerability is the function runApp of the file src/index.…

Fix: 2020-11-02+
Fix from $1,600 2022-12-21
Pie Register MEDIUM 6.5
CVE-2022-4024

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing …

Fix: 3.8.1.3+
Fix from $1,600 2022-12-19
Wp English Wp Admin HIGH 8.8
CVE-2022-4604

A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerability is the function registe…

Fix: 1.5.2+
Fix from $1,950 2022-12-18
Materia HIGH 8.8
CVE-2022-4564

A vulnerability classified as problematic has been found in University of Central Florida Materia up to 9.0.0. This affects the function before of th…

Fix: after 9.0.0
Fix from $1,950 2022-12-16
Corner Ad MEDIUM 6.5
CVE-2022-3427

The Corner Ad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.56. This is due to missing or in…

Fix: after 1.0.56
Fix from $1,600 2022-12-15
Helmet Store Showroom HIGH 8.8
CVE-2022-46074

Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF pr…

No fix yet
Fix from $1,950 2022-12-14
Aerocms MEDIUM 6.5
CVE-2022-46059

AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).

No fix yet
Fix from $1,600 2022-12-13
Welcart E Commerce MEDIUM 6.5
CVE-2022-3946

The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, u…

Fix: 2.8.4+
Fix from $1,600 2022-12-12
Woocommerce Shipping HIGH 8.1
CVE-2022-3999

The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated us…

Fix: after 1.2.11
Fix from $1,950 2022-12-12
Car Dealer MEDIUM 6.5
CVE-2022-3879

The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX ac…

Fix: 3.05+
Fix from $1,600 2022-12-12
Antihacker MEDIUM 6.5
CVE-2022-3880

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper auth…

Fix: 4.20+
Fix from $1,600 2022-12-12
Wptools MEDIUM 5.7
CVE-2022-3881

The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.4…

Fix: 3.43+
Fix from $1,600 2022-12-12
Wp Memory MEDIUM 6.5
CVE-2022-3882

The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and…

Fix: 2.46+
Fix from $1,600 2022-12-12
Stopbadbots MEDIUM 6.5
CVE-2022-3883

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not have proper authorisation an…

Fix: 7.24+
Fix from $1,600 2022-12-12
Supra Csv Parser MEDIUM 5.4
CVE-2022-3853

Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a web browser of the victim by i…

Fix: after 4.0.3
Fix from $1,600 2022-12-12
Ax12 Firmware HIGH 8.8
CVE-2022-45980EPSS 7%

Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .

No fix yet
Fix from $1,950 2022-12-12
Sonar Gerrit MEDIUM 6.5
CVE-2022-46688

A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins conne…

Fix: after 377.v8f3808963dc5
Fix from $1,600 2022-12-12
Db2 HIGH 8.8
CVE-2022-41296

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Mitigation only
Fix from $1,950 2022-12-12
Zend Blog 2 MEDIUM 6.5
CVE-2022-4397

A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file applicati…

Patch available
Fix from $1,600 2022-12-10