Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Nas1dual Firmware HIGH 8.8
CVE-2022-23765

This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote …

Fix: 1.4.86+
Fix from $1,950 2022-08-17
Airvelocity 1500 Firmware HIGH 8.8
CVE-2022-36312

Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelo…

Mitigation only
Fix from $1,950 2022-08-16
Eyes Of Network Web HIGH 8.8
CVE-2022-38359

Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An atta…

No fix yet
Fix from $1,950 2022-08-15
E Unlocked Student Result HIGH 8.8
CVE-2022-2381

The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attac…

Fix: after 1.0.4
Fix from $1,950 2022-08-15
Codeigniter HIGH 8.8
CVE-2022-35943

Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubd…

Fix: 4.2.3+
Fix from $1,950 2022-08-12
Collaboration MEDIUM 5.7
CVE-2022-37043

An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked …

Patch available
Fix from $1,600 2022-08-12
Easy Username Updater MEDIUM 6.5
CVE-2022-2355

The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change …

Fix: 1.0.5+
Fix from $1,600 2022-08-08
Mailerlite Signup Forms HIGH 8.8
CVE-2022-33201

Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the…

Fix: 1.5.8+
Fix from $1,950 2022-08-05
Administrate MEDIUM 5.4
CVE-2016-3098

Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization cod…

Fix: 0.1.5+
Fix from $1,600 2022-08-05
Jspwiki MEDIUM 6.5
CVE-2022-28731EPSS 57%

A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacke…

Fix: 2.11.3+
Fix from $1,600 2022-08-04
Jspwiki HIGH 8.8
CVE-2022-34158

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group pri…

Fix: 2.11.3+
Fix from $1,950 2022-08-04
U5cms HIGH 8.8
CVE-2022-34937

Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers t…

No fix yet
Fix from $1,950 2022-08-03
Cics Tx HIGH 8.8
CVE-2022-34161

IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Patch available
Fix from $1,950 2022-08-01
Progressive License MEDIUM 5.4
CVE-2022-2171

The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logg…

Fix: after 1.1.0
Fix from $1,600 2022-08-01
Captcha 4wp HIGH 8.8
CVE-2022-2184

The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abu…

Fix: 7.1.0+
Fix from $1,950 2022-08-01
Counter Box HIGH 8.8
CVE-2022-2245

The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a …

Fix: 1.2.1+
Fix from $1,950 2022-08-01
Givewp MEDIUM 6.5
CVE-2022-2260

The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dat…

Fix: 2.21.3+
Fix from $1,600 2022-08-01
Pandora Fms HIGH 8.8
CVE-2022-26309

Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator grou…

Fix: after 7.0_ng_759
Fix from $1,950 2022-08-01
Coverity HIGH 8.8
CVE-2022-36920

A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified …

Fix: after 1.11.4
Fix from $1,950 2022-07-27
Google Cloud Backup HIGH 8.0
CVE-2022-36916

A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup.

Fix: after 0.6
Fix from $1,950 2022-07-27
Openshift Deployer MEDIUM 6.5
CVE-2022-36906

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to connect to an attacker-s…

Fix: after 1.2.0
Fix from $1,600 2022-07-27
Openshift Deployer MEDIUM 6.5
CVE-2022-36908

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence …

Fix: after 1.2.0
Fix from $1,600 2022-07-27
Openstack Heat MEDIUM 6.5
CVE-2022-36911

A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers to connect to an attacker-specifi…

Fix: after 1.5
Fix from $1,600 2022-07-27
Git HIGH 8.8
CVE-2022-36882

A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to u…

Fix: after 4.11.3
Fix from $1,950 2022-07-27
Security Verify Information Queue HIGH 8.8
CVE-2022-35286

IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2022-07-26
Calendar HIGH 8.0
CVE-2022-22686

Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijac…

Fix: 2.3.4-0631+
Fix from $1,950 2022-07-26
Security Verify Information Queue HIGH 8.8
CVE-2022-35285

IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2022-07-25
Modular Switchgear Monitoring Firmware HIGH 8.8
CVE-2021-40335

A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was…

Fix: after 2.2.0
Fix from $1,950 2022-07-25
Name Directory MEDIUM 6.1
CVE-2022-2071

The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping…

Fix: 1.25.4+
Fix from $1,600 2022-07-25
Emc Data Protection Central HIGH 8.8
CVE-2022-34367

Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unau…

Fix: 19.7+
Fix from $1,950 2022-07-21