Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Corehr Core Portal HIGH 8.8
CVE-2019-25064

A vulnerability was found in CoreHR Core Portal up to 27.0.7. It has been classified as problematic. Affected is an unknown function. The manipulatio…

Fix: after 27.0.7
Fix from $1,950 2022-06-09
Discy MEDIUM 6.5
CVE-2022-1422

The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin in…

Fix: 5.2+
Fix from $1,600 2022-06-08
Ask Me MEDIUM 6.5
CVE-2022-1424

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to pe…

Fix: 6.8.2+
Fix from $1,600 2022-06-08
Files Download Delay MEDIUM 6.5
CVE-2022-1570

The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any …

Fix: 1.0.7+
Fix from $1,600 2022-06-08
Database Backup MEDIUM 5.4
CVE-2022-1577

The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow…

Fix: 2.5.2+
Fix from $1,600 2022-06-08
Easyiicms MEDIUM 6.5
CVE-2020-36534

A vulnerability was found in easyii CMS. It has been classified as problematic. Affected is an unknown function of the file /admin/sign/out. The mani…

No fix yet
Fix from $1,600 2022-06-07
Entelitouch Firmware HIGH 8.8
CVE-2022-29735

Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request.

No fix yet
Fix from $1,950 2022-06-02
Mcms HIGH 8.8
CVE-2022-29647

An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

No fix yet
Fix from $1,950 2022-06-02
Pbootcms HIGH 8.8
CVE-2020-20971

Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.

No fix yet
Fix from $1,950 2022-06-02
Business Automation Workflow MEDIUM 6.5
CVE-2022-22361

IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, …

Fix: after 21.0.3
Fix from $1,600 2022-05-31
All In One Login HIGH 7.5
CVE-2022-1589

The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its se…

Fix: 1.1.0+
Fix from $1,950 2022-05-30
Bulk Page Creator HIGH 8.8
CVE-2022-1611

The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable…

Fix: 1.1.4+
Fix from $1,950 2022-05-30
Jivochat MEDIUM 5.4
CVE-2022-0642

The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not s…

Fix: 1.3.5.4+
Fix from $1,600 2022-05-30
Nas Proxy Server HIGH 8.8
CVE-2021-34360

A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allo…

Fix: 1.4.2 / 1.4.3+
Fix from $1,950 2022-05-26
Xxl Job HIGH 8.8
CVE-2022-29002

A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin…

No fix yet
Fix from $1,950 2022-05-23
Simple Food Website HIGH 8.8
CVE-2022-30014

Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.

Mitigation only
Fix from $1,950 2022-05-23
Disable Right Click For Wp HIGH 8.8
CVE-2022-29427

Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress.

Fix: after 1.1.6
Fix from $1,950 2022-05-20
Png To Jpg MEDIUM 6.1
CVE-2022-29430

Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin <= 4.0 at WordPress via Cross-Site Request Forgery (CSRF). Vulnerable parameter…

Fix: after 4.0
Fix from $1,600 2022-05-20
Cpt Base MEDIUM 5.4
CVE-2022-29431

Cross-Site Request Forgery (CSRF) vulnerability in KubiQ CPT base plugin <= 5.8 at WordPress allows an attacker to delete the CPT base.

Fix: after 5.8
Fix from $1,600 2022-05-20
Online Banquet Booking System HIGH 8.8
CVE-2022-28992

A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request.

No fix yet
Fix from $1,950 2022-05-20
Blogengine.net MEDIUM 6.5
CVE-2022-28921

A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on t…

No fix yet
Fix from $1,600 2022-05-18
Businessconnect Trading Community Management HIGH 8.8
CVE-2022-22778

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability tha…

Fix: 6.1.1+
Fix from $1,950 2022-05-18
Watch Boot Nino Rpc M2c Firmware HIGH 8.8
CVE-2022-27632

Cross-site request forgery (CSRF) vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT light RPC-M5C [En…

Fix: after 1.20a
Fix from $1,950 2022-05-18
Code Snippets Extended MEDIUM 5.4
CVE-2022-29435

Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress allows an attacker to del…

Fix: after 1.4.7
Fix from $1,600 2022-05-17
Code Snippets Extended MEDIUM 6.1
CVE-2022-29436

Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Reques…

Fix: after 1.4.7
Fix from $1,600 2022-05-17
Code Snippets Extended HIGH 8.8
CVE-2022-29429

Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery.

Fix: after 1.4.7
Fix from $1,950 2022-05-17
Autocomplete Parameter HIGH 8.8
CVE-2022-30969

A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code…

Fix: after 1.1
Fix from $1,950 2022-05-17
Storage Configs HIGH 8.8
CVE-2022-30972

A cross-site request forgery (CSRF) vulnerability in Jenkins Storable Configs Plugin 1.0 and earlier allows attackers to have Jenkins parse a local X…

Fix: after 1.0
Fix from $1,950 2022-05-17
Ssh HIGH 8.8
CVE-2022-30958

A cross-site request forgery (CSRF) vulnerability in Jenkins SSH Plugin 2.6.1 and earlier allows attackers to connect to an attacker-specified SSH se…

Fix: after 2.6.1
Fix from $1,950 2022-05-17
Blue Ocean MEDIUM 6.5
CVE-2022-30953

A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specifie…

Fix: after 1.25.3
Fix from $1,600 2022-05-17