Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Nexus Dashboard HIGH 8.8
CVE-2022-20861

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…

Fix: 2.2+
Fix from $1,950 2022-07-21
Partner Engagement Manager MEDIUM 6.5
CVE-2022-22359

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to …

Fix: 6.1.2.5 / 6.2.0.3+
Fix from $1,600 2022-07-19
Engineering Requirements Quality Assistant On Premises MEDIUM 6.5
CVE-2021-38868

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker t…

Mitigation only
Fix from $1,600 2022-07-18
Anymind Widget HIGH 8.8
CVE-2022-2435

The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1. This is due to missing nonc…

Fix: after 1.1
Fix from $1,950 2022-07-18
Freemind Wp Browser HIGH 8.8
CVE-2022-2443

The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing…

Fix: after 1.2
Fix from $1,950 2022-07-18
Button Widget Smartsoft HIGH 8.8
CVE-2022-1912

The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to …

Patch available
Fix from $1,950 2022-07-18
Dx Share Selection HIGH 8.8
CVE-2022-2001

The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing …

Fix: 1.5+
Fix from $1,950 2022-07-18
Free Live Chat Support HIGH 8.8
CVE-2022-2039

The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.11. This is due to m…

Fix: after 1.0.11
Fix from $1,950 2022-07-18
Ferdium HIGH 8.8
CVE-2022-32320

A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file s…

Fix: after 5.8.1
Fix from $1,950 2022-07-17
Insights From Google Pagespeed HIGH 8.8
CVE-2022-1672

The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, …

Fix: 4.0.7+
Fix from $1,950 2022-07-17
Import Csv Files MEDIUM 6.1
CVE-2022-2146

The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking C…

Fix: after 1.0
Fix from $1,600 2022-07-17
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2022-35228

SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This c…

Mitigation only
Fix from $1,950 2022-07-12
Cache Images MEDIUM 6.5
CVE-2022-2091

The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via…

Fix: 3.2.1+
Fix from $1,600 2022-07-11
Wp Maintenance Mode \& Coming Soon MEDIUM 6.5
CVE-2022-1576

The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attack…

Fix: 2.4.5+
Fix from $1,600 2022-07-11
Admin Management Xtended MEDIUM 6.5
CVE-2022-1599

The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged…

Fix: 2.4.5+
Fix from $1,600 2022-07-11
Sharebar MEDIUM 5.4
CVE-2022-1626

The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logge…

Fix: after 1.4.1
Fix from $1,600 2022-07-11
Rename Wp Login MEDIUM 6.5
CVE-2022-1732

The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login URL, which could allow attack…

Fix: after 2.6.0
Fix from $1,600 2022-07-11
Pagebar MEDIUM 5.4
CVE-2022-1757

The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged i…

Fix: 2.70+
Fix from $1,600 2022-07-11
Microweber MEDIUM 6.1
CVE-2022-2353

Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, …

Fix: 1.2.20+
Fix from $1,600 2022-07-09
Nextgen Gallery MEDIUM 6.5
CVE-2015-1785

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web applica…

Fix: 2.0.77.3+
Fix from $1,600 2022-07-07
Pescms Team MEDIUM 6.5
CVE-2021-31677

An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwords.

No fix yet
Fix from $1,600 2022-07-06
Pescms Team MEDIUM 6.5
CVE-2021-31678

An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user's company.

No fix yet
Fix from $1,600 2022-07-06
Pescms Team MEDIUM 6.5
CVE-2021-31679

An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other members' account numbers.

No fix yet
Fix from $1,600 2022-07-06
Artifactory HIGH 8.8
CVE-2021-23163

JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects…

Fix: 6.23.38 / 7.33.6+
Fix from $1,950 2022-07-06
Wp Championship MEDIUM 6.5
CVE-2022-1967

The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwant…

Fix: 9.3+
Fix from $1,600 2022-07-04
Recipe HIGH 8.0
CVE-2022-34792

A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-sp…

Fix: after 1.2
Fix from $1,950 2022-06-30
Matrix Reloaded MEDIUM 6.5
CVE-2022-34789

A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix bui…

Fix: after 1.1.3
Fix from $1,600 2022-06-30
Xebialabs Xl Release MEDIUM 6.5
CVE-2022-34780

A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacke…

Fix: after 22.0.0
Fix from $1,600 2022-06-30
Trueconf Server HIGH 8.8
CVE-2017-20120

A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop…

No fix yet
Fix from $1,950 2022-06-29
Marval Msm MEDIUM 6.5
CVE-2022-31886

Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.

No fix yet
Fix from $1,600 2022-06-28