Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Aos Cx HIGH 8.8
CVE-2022-23679

AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attacker to execute commands in th…

Fix: 10.06.0210 / 10.08.1070+
Fix from $1,950 2022-09-06
Aos Cx HIGH 8.8
CVE-2022-23680

AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attacker to execute commands in th…

Fix: 10.06.0210 / 10.08.1070+
Fix from $1,950 2022-09-06
Online Employee Leave Management System HIGH 8.8
CVE-2022-3121

A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problematic. Affected by this vulner…

Mitigation only
Fix from $1,950 2022-09-05
Nodebb HIGH 7.5
CVE-2022-36076

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional …

Fix: 1.17.2+
Fix from $1,950 2022-09-02
Cognos Analytics MEDIUM 6.5
CVE-2020-4301

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Cognos Analytics MEDIUM 6.5
CVE-2021-20468

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Cognos Analytics MEDIUM 6.5
CVE-2021-29823

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Mp3 Jplayer HIGH 8.8
CVE-2022-36373

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress.

Fix: after 2.7.3
Fix from $1,950 2022-09-01
Callrail Phone Call Tracking MEDIUM 6.1
CVE-2022-36796

Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in CallRail, Inc. CallRail Phone Call Tracking plugin <=…

Fix: after 0.4.9
Fix from $1,600 2022-09-01
Froxlor MEDIUM 6.5
CVE-2022-3017

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.

Fix: 0.10.38+
Fix from $1,600 2022-08-28
Edoc Doctor Appointment System HIGH 8.8
CVE-2022-36546

Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php.

No fix yet
Fix from $1,950 2022-08-26
Datapower Gateway HIGH 8.8
CVE-2022-31773

IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Fix: 10.5.0+
Fix from $1,950 2022-08-26
Mm Wiki MEDIUM 6.5
CVE-2021-39394

mm-wiki v0.2.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add user accounts and modify user …

No fix yet
Fix from $1,600 2022-08-26
Download Manager HIGH 8.8
CVE-2022-36288

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

Fix: after 3.2.48
Fix from $1,950 2022-08-23
Gallery Photoblocks HIGH 8.8
CVE-2022-36292

Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.

Fix: after 1.2.6
Fix from $1,950 2022-08-23
Yukassa For Woocommerce HIGH 8.8
CVE-2022-36379

Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.

Fix: after 2.3.0
Fix from $1,950 2022-08-23
Better Messages HIGH 8.8
CVE-2022-36389

Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress.

Fix: after 1.9.9.148
Fix from $1,950 2022-08-23
Avideo HIGH 8.8
CVE-2022-29468

A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lea…

No fix yet
Fix from $1,950 2022-08-22
Download Manager HIGH 8.8
CVE-2022-34347

Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

Fix: after 3.2.48
Fix from $1,950 2022-08-22
Maxbuttons HIGH 8.8
CVE-2022-36346

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.

Fix: after 9.2
Fix from $1,950 2022-08-22
Yotpo Reviews For Woocommerce MEDIUM 6.5
CVE-2022-2555

The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a l…

Fix: after 2.0.4
Fix from $1,600 2022-08-22
Student Result Or Employee Database MEDIUM 5.4
CVE-2022-2312

The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in us…

Fix: 1.7.5+
Fix from $1,600 2022-08-22
Wp Sticky Button MEDIUM 5.4
CVE-2022-2375

The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated use…

Fix: 1.4.1+
Fix from $1,600 2022-08-22
Wp Coder MEDIUM 6.5
CVE-2022-2388

The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to…

Fix: 2.5.3+
Fix from $1,600 2022-08-22
Wp Hotel Booking HIGH 8.0
CVE-2021-36852

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.

Fix: after 1.10.5
Fix from $1,950 2022-08-22
Transposh Wordpress Translation MEDIUM 5.4
CVE-2021-24912

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attac…

Fix: 1.0.8+
Fix from $1,600 2022-08-22
Jizhicms HIGH 8.8
CVE-2022-36577

An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.

No fix yet
Fix from $1,950 2022-08-19
Wellcms HIGH 8.8
CVE-2022-36579

Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).

No fix yet
Fix from $1,950 2022-08-19
Xunruicms HIGH 8.8
CVE-2022-36224

XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).

No fix yet
Fix from $1,950 2022-08-19
Eyoucms HIGH 8.8
CVE-2022-36225

EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.

No fix yet
Fix from $1,950 2022-08-19