Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Online Birth Certificate Management System HIGH 8.8
CVE-2022-42070

Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).

No fix yet
Fix from $1,950 2022-10-14
Rpcms MEDIUM 6.5
CVE-2022-41474

RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily change the password of any account.

No fix yet
Fix from $1,600 2022-10-13
Rpcms HIGH 8.8
CVE-2022-41475

RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator account.

No fix yet
Fix from $1,950 2022-10-13
Lq 09 Firmware HIGH 8.1
CVE-2022-41489

WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server fro…

No fix yet
Fix from $1,950 2022-10-13
Iot Platform And Lorawan Network Server HIGH 8.8
CVE-2022-34020

Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add ne…

Fix: after 4.1.1000114
Fix from $1,950 2022-10-13
Ac1206 Firmware MEDIUM 6.5
CVE-2022-42077

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

No fix yet
Fix from $1,600 2022-10-12
Ac1206 Firmware MEDIUM 6.5
CVE-2022-42078

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

No fix yet
Fix from $1,600 2022-10-12
Ax1803 Firmware MEDIUM 6.5
CVE-2022-42086

Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.

No fix yet
Fix from $1,600 2022-10-12
Ax1803 Firmware MEDIUM 6.5
CVE-2022-42087

Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

No fix yet
Fix from $1,600 2022-10-12
Adguardhome MEDIUM 5.4
CVE-2022-32175

In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality…

Fix: 0.108+
Fix from $1,600 2022-10-11
Desigo Pxm30 1 Firmware HIGH 8.1
CVE-2022-40179

A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM…

Fix: 02.20.126.11-37 / 02.20.126.11-41+
Fix from $1,950 2022-10-11
Desigo Pxm30 1 Firmware MEDIUM 5.3
CVE-2022-40180

A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM…

Fix: 02.20.126.11-37 / 02.20.126.11-41+
Fix from $1,600 2022-10-11
Woo Billingo Plus HIGH 7.1
CVE-2022-3154

The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamla…

Fix: 1.0.4 / 1.2.7+
Fix from $1,950 2022-10-10
Simple File List MEDIUM 6.5
CVE-2022-3208

The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new…

Fix: 4.4.12+
Fix from $1,600 2022-10-10
Disable User Login MEDIUM 5.3
CVE-2022-2350

The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticate…

Fix: after 1.0.1
Fix from $1,600 2022-10-10
Websphere Automation For Ibm Cloud Pak For Watson Aiops HIGH 8.8
CVE-2022-22493

IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute settin…

Fix: 1.4.3+
Fix from $1,950 2022-10-07
Moodle HIGH 8.8
CVE-2022-2986

Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.

Fix: 3.11.9 / 4.0.3+
Fix from $1,950 2022-10-06
Octopus Server MEDIUM 5.3
CVE-2022-2783

In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token

Fix: 2022.1.3154 / 2022.2.7897+
Fix from $1,600 2022-10-06
Zephyr Project Manager MEDIUM 5.4
CVE-2022-2839

The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthent…

Fix: 3.2.55+
Fix from $1,600 2022-10-03
Orchest HIGH 8.1
CVE-2022-39268

### Impact In a CSRF attack, an innocent end user is tricked by an attacker into submitting a web request that they did not intend. This may cause ac…

Fix: after 2022.09.9
Fix from $1,950 2022-09-30
Booking Ultra Pro Appointments Booking Calendar HIGH 8.8
CVE-2021-36854

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress.

Fix: after 1.1.4
Fix from $1,950 2022-09-30
Booking Ultra Pro Appointments Booking Calendar MEDIUM 6.1
CVE-2021-36855

Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress.

Fix: after 1.1.4
Fix from $1,600 2022-09-30
Online Invoicing System HIGH 8.8
CVE-2020-35675

BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups. The appl…

Fix: 3.0+
Fix from $1,950 2022-09-29
Chrome MEDIUM 6.5
CVE-2022-3057

Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a craf…

Fix: 105.0.5195.52+
Fix from $1,600 2022-09-26
Oauth Client Single Sign On HIGH 7.5
CVE-2022-3119

The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unau…

Fix: 3.0.4+
Fix from $1,950 2022-09-26
Ldap Wp Login \/ Active Directory Integration HIGH 7.5
CVE-2022-2987

The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's set…

Fix: 3.0.2+
Fix from $1,950 2022-09-26
Simple Bitcoin Faucets MEDIUM 5.4
CVE-2022-3024

The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated user…

Fix: after 1.7.0
Fix from $1,600 2022-09-26
Bitcoin\/altcoin Faucet MEDIUM 5.4
CVE-2022-3025

The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged…

Fix: after 1.6.0
Fix from $1,600 2022-09-26
Scripts Organizer HIGH 8.8
CVE-2021-24890

The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthent…

Fix: 3.0+
Fix from $1,950 2022-09-26
Backup Scheduler HIGH 8.8
CVE-2022-38079

Cross-Site Request Forgery (CSRF) vulnerability Backup Scheduler plugin <= 1.5.13 at WordPress.

Fix: after 1.5.13
Fix from $1,950 2022-09-23