Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Pwn MEDIUM 6.8
CVE-2022-4349

A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation le…

No fix yet
Fix from $1,600 2022-12-08
Big Iq Centralized Management HIGH 8.8
CVE-2022-41622EPSS 88%

In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.   Note: Software versions wh…

Fix: after 16.1.3
Fix from $1,950 2022-12-07
Metinfo HIGH 8.8
CVE-2022-44849

A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.

No fix yet
Fix from $1,950 2022-12-07
Daloradius HIGH 8.8
CVE-2022-23475

daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) a…

Fix: 1.3+
Fix from $1,950 2022-12-06
Wp Oauth Server MEDIUM 6.5
CVE-2022-3926

The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attack…

Fix: 3.4.2+
Fix from $1,600 2022-12-05
Advanced Booking Calendar MEDIUM 6.5
CVE-2022-45824

Cross-Site Request Forgery (CSRF) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.

Fix: after 1.7.1
Fix from $1,600 2022-12-05
Fs040u Firmware HIGH 7.3
CVE-2022-43470

Cross-site request forgery (CSRF) vulnerability in +F FS040U software versions v2.3.4 and earlier, +F FS020W software versions v4.0.0 and earlier, +F…

Fix: after 4.0.0
Fix from $1,950 2022-12-05
Sticky Header MEDIUM 6.5
CVE-2022-35730

Cross-Site Request Forgery (CSRF) vulnerability in Oceanwp sticky header plugin <= 1.0.8 on WordPress.

Fix: after 1.0.8
Fix from $1,600 2022-12-04
I22 Firmware MEDIUM 6.5
CVE-2022-45667

Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

No fix yet
Fix from $1,600 2022-12-02
I22 Firmware MEDIUM 6.5
CVE-2022-45668

Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

No fix yet
Fix from $1,600 2022-12-02
Ac6 Firmware MEDIUM 6.5
CVE-2022-45673

Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

No fix yet
Fix from $1,600 2022-12-02
Ac6 Firmware MEDIUM 6.5
CVE-2022-45674

Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

No fix yet
Fix from $1,600 2022-12-02
Db2 On Cloud Pak For Data MEDIUM 6.5
CVE-2022-41297

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Fix: 4.6+
Fix from $1,600 2022-12-01
Thinkcmf HIGH 8.8
CVE-2022-40489

ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into ad…

No fix yet
Fix from $1,950 2022-12-01
Adrotate Banner Manager HIGH 8.8
CVE-2022-26366

Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress.

Fix: after 5.9
Fix from $1,950 2022-11-30
Becustom MEDIUM 6.5
CVE-2022-3747

The Becustom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.2. This is due to missing nonce…

Fix: after 1.0.5.2
Fix from $1,600 2022-11-29
Wp Affiliate Platform MEDIUM 6.5
CVE-2022-3898

The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to mi…

Fix: after 6.3.9
Fix from $1,600 2022-11-29
Bosscms MEDIUM 6.5
CVE-2022-44937

Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module.

No fix yet
Fix from $1,600 2022-11-28
Manage Notification E Mails HIGH 8.8
CVE-2022-34654

Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notification E-mails plugin <= 1.8.2 on WordPress.

Fix: 1.8.3+
Fix from $1,950 2022-11-28
Tiny File Manager HIGH 8.8
CVE-2022-23044

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. Thi…

No fix yet
Fix from $1,950 2022-11-25
Stock Management System HIGH 8.8
CVE-2022-4090

A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_…

No fix yet
Fix from $1,950 2022-11-24
Jizhicms HIGH 8.8
CVE-2021-29334

An issue was discovered in JIZHI CMS 1.9.4. There is a CSRF vulnerability that can add an admin account via index, /admin.php/Admin/adminadd.html

Mitigation only
Fix from $1,950 2022-11-23
Tailscale CRITICAL 9.6
CVE-2022-41924

A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can the…

Fix: 1.32.3+
Fix from $2,300 2022-11-23
Tailscale HIGH 8.8
CVE-2022-41925

A vulnerability identified in the Tailscale client allows a malicious website to access the peer API, which can then be used to access Tailscale envi…

Fix: 1.32.3+
Fix from $1,950 2022-11-23
Xwiki HIGH 7.4
CVE-2022-41927

XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation.…

Fix: 13.10.7+
Fix from $1,950 2022-11-23
Moodle MEDIUM 5.4
CVE-2022-45149

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF toke…

Fix: 3.9.18 / 3.11.11+
Fix from $1,600 2022-11-23
Op Xt71000n Firmware MEDIUM 6.5
CVE-2020-23589

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to con…

Mitigation only
Fix from $1,600 2022-11-23
Op Xt71000n Firmware MEDIUM 6.5
CVE-2020-23590

A vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated remote attacker to cond…

Mitigation only
Fix from $1,600 2022-11-23
Op Xt71000n Firmware HIGH 8.8
CVE-2020-23592

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to con…

Mitigation only
Fix from $1,950 2022-11-23
Op Xt71000n Firmware HIGH 8.8
CVE-2020-23585

A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1…

Mitigation only
Fix from $1,950 2022-11-23