Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Kraken.io Image Optimizer HIGH 8.8
CVE-2022-38454

Cross-Site Request Forgery (CSRF) vulnerability in Kraken.io Image Optimizer plugin <= 2.6.5 at WordPress.

Fix: after 2.6.5
Fix from $1,950 2022-09-23
3d Tag Cloud MEDIUM 6.1
CVE-2022-36417

Multiple Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in 3D Tag Cloud plugin <= 3.8 at WordPress.

Fix: after 3.8
Fix from $1,600 2022-09-23
Customer Reviews For Woocommerce HIGH 8.8
CVE-2022-38470

Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.

Fix: after 5.3.5
Fix from $1,950 2022-09-23
Yds Support Ticket System HIGH 8.8
CVE-2022-36388

Cross-Site Request Forgery (CSRF) vulnerability in YDS Support Ticket System plugin <= 1.0 at WordPress.

Fix: after 1.0
Fix from $1,950 2022-09-23
Read More By Adam HIGH 8.8
CVE-2022-38085

Cross-Site Request Forgery (CSRF) vulnerability in Read more By Adam plugin <= 1.1.8 at WordPress.

Fix: after 1.1.8
Fix from $1,950 2022-09-23
Mega Addons For Wpbakery Page Builder HIGH 8.8
CVE-2022-36798

Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin <= 4.2.7 at WordPress.

Fix: after 4.2.7
Fix from $1,950 2022-09-23
Worksoft Execution Manager HIGH 8.8
CVE-2022-41245

A cross-site request forgery (CSRF) vulnerability in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers to connect to …

Fix: after 10.0.3.503
Fix from $1,950 2022-09-21
Scm Httpclient HIGH 8.8
CVE-2022-41249

A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to connect to an attacker-specifi…

Fix: after 1.5
Fix from $1,950 2022-09-21
Cons3rt HIGH 8.8
CVE-2022-41253

A cross-site request forgery (CSRF) vulnerability in Jenkins CONS3RT Plugin 1.0.0 and earlier allows attackers to connect to an attacker-specified HT…

Fix: after 1.0.0
Fix from $1,950 2022-09-21
Ns Nd Integration Performance Publisher HIGH 8.8
CVE-2022-41227

A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to…

Fix: 4.8.0.130+
Fix from $1,950 2022-09-21
Build Publisher HIGH 8.0
CVE-2022-41232

A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to replace any config.xml file …

Fix: after 1.22
Fix from $1,950 2022-09-21
Security Inspector HIGH 8.8
CVE-2022-41236

A cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier allows attackers to replace the …

Fix: after 117.v6eecc36919c2
Fix from $1,950 2022-09-21
Clearpass Policy Manager HIGH 8.8
CVE-2022-23685

A vulnerability in the ClearPass Policy Manager web-based management interface exists which exposes some endpoints to a lack of Cross-Site Request Fo…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2022-09-20
Testlink HIGH 8.8
CVE-2022-35196

TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

No fix yet
Fix from $1,950 2022-09-20
Rdiffweb HIGH 8.8
CVE-2022-3221

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.

Fix: 2.4.3+
Fix from $1,950 2022-09-15
Wn531g3 Firmware HIGH 8.8
CVE-2022-40623

The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 does not utilize anti-CSRF tokens, which, when combined with other issu…

No fix yet
Fix from $1,950 2022-09-13
Data Exchange Management Studio HIGH 8.8
CVE-2022-32555

Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, …

Mitigation only
Fix from $1,950 2022-09-13
Rd Station HIGH 8.8
CVE-2022-38139

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in RD Station plugin <= 5.2.0 at WordPress.

Fix: after 5.2.0
Fix from $1,950 2022-09-13
All In One Seo HIGH 8.8
CVE-2022-38093

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress.

Fix: after 4.2.3.1
Fix from $1,950 2022-09-09
Wpforo Forum HIGH 8.8
CVE-2022-38144

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.

Fix: after 2.0.5
Fix from $1,950 2022-09-09
Better Font Awesome HIGH 8.8
CVE-2022-37405

Cross-Site Request Forgery (CSRF) vulnerability in Mickey Kay's Better Font Awesome plugin <= 2.0.1 at WordPress.

Fix: after 2.0.1
Fix from $1,950 2022-09-09
Captcha Code HIGH 8.8
CVE-2022-37411

Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza's Captcha Code plugin <= 2.7 at WordPress.

Fix: after 2.7
Fix from $1,950 2022-09-09
Access Code Feeder HIGH 8.0
CVE-2022-38059

Cross-Site Request Forgery (CSRF) vulnerability in Alexey Trofimov's Access Code Feeder plugin <= 1.0.3 at WordPress.

Fix: after 1.0.3
Fix from $1,950 2022-09-09
Getresponse HIGH 8.8
CVE-2022-35277

Cross-Site Request Forgery (CSRF) vulnerability in GetResponse plugin <= 5.5.20 at WordPress.

Fix: after 5.5.20
Fix from $1,950 2022-09-09
Ftcms HIGH 8.8
CVE-2022-37730

In ftcms 2.1, there is a Cross Site Request Forgery (CSRF) vulnerability in the PHP page, which causes the attacker to forge a link to trick him to c…

No fix yet
Fix from $1,950 2022-09-07
Stockists Manager For Woocommerce MEDIUM 6.1
CVE-2022-2518

The Stockists Manager for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2.1. Thi…

Fix: after 1.0.2.1
Fix from $1,600 2022-09-06
Link Optimizer Lite HIGH 8.8
CVE-2022-2540

The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 1.4…

Fix: after 1.4.5
Fix from $1,950 2022-09-06
Ucontext For Amazon HIGH 8.8
CVE-2022-2541

The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9…

Fix: after 3.9.1
Fix from $1,950 2022-09-06
Ucontext For Clickbank HIGH 8.8
CVE-2022-2542

The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including …

Fix: after 3.9.1
Fix from $1,950 2022-09-06
Banner Cycler HIGH 8.8
CVE-2022-2233

The Banner Cycler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing nonce…

Fix: after 1.4
Fix from $1,950 2022-09-06