Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Access Demo Importer MEDIUM 6.5
CVE-2022-23975

Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin.

Fix: after 1.0.7
Fix from $1,600 2022-04-18
Access Demo Importer HIGH 8.1
CVE-2022-23976

Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media).

Fix: after 1.0.7
Fix from $1,950 2022-04-18
Selenium Grid HIGH 8.8
CVE-2022-28109

Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The impact is: execute arbitrary c…

Fix: 4.0.0+
Fix from $1,950 2022-04-15
Catalyst Sd Wan Manager MEDIUM 6.5
CVE-2022-20735

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a c…

Fix: 20.6.1+
Fix from $1,600 2022-04-15
Pluck MEDIUM 6.5
CVE-2022-26589

A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.

Mitigation only
Fix from $1,600 2022-04-13
Publish Over Ftp HIGH 8.8
CVE-2022-29050

A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over FTP Plugin 1.16 and earlier allows attackers to connect to an FTP server us…

Fix: after 1.16
Fix from $1,950 2022-04-12
Calderawp License Manager MEDIUM 6.1
CVE-2021-36914

Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Manager (WordPress plugin) <= 1.…

Fix: after 1.2.11
Fix from $1,600 2022-04-12
Visual Form Builder HIGH 8.1
CVE-2022-0141

The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor d…

Fix: 3.0.6+
Fix from $1,950 2022-04-12
Scalance X302 7eec Firmware HIGH 8.8
CVE-2022-25754

A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC…

Fix: 4.1.4+
Fix from $1,950 2022-04-12
Export All Urls MEDIUM 6.5
CVE-2022-0914

The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admi…

Fix: 4.3+
Fix from $1,600 2022-04-11
Webmin HIGH 8.8
CVE-2021-32156

A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

No fix yet
Fix from $1,950 2022-04-11
Webmin HIGH 8.8
CVE-2021-32159

A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

No fix yet
Fix from $1,950 2022-04-11
Webmin HIGH 8.8
CVE-2021-32162

A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.

No fix yet
Fix from $1,950 2022-04-11
Qdpm HIGH 8.8
CVE-2022-26180

qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.

No fix yet
Fix from $1,950 2022-04-08
Icehrm MEDIUM 6.5
CVE-2022-26588

A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.ph…

No fix yet
Fix from $1,600 2022-04-08
Sterling B2b Integrator HIGH 8.8
CVE-2020-4668

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forger…

Fix: after 6.1.0.3
Fix from $1,950 2022-04-08
Ip Phone 6871 Firmware HIGH 8.1
CVE-2022-20774

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauth…

Fix: 11.3.5+
Fix from $1,950 2022-04-06
Itop HIGH 8.1
CVE-2021-41245

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't…

Fix: 2.7.6+
Fix from $1,950 2022-04-05
Formbuilder MEDIUM 6.5
CVE-2022-0830

The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as …

Fix: after 1.08
Fix from $1,600 2022-04-04
Yourls HIGH 7.4
CVE-2022-0088

Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.

Fix: 1.8.3+
Fix from $1,950 2022-04-03
Firmware Analysis And Comparison Tool HIGH 8.8
CVE-2021-44312

An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a…

No fix yet
Fix from $1,950 2022-03-30
Pluck HIGH 8.8
CVE-2022-27432

A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading…

No fix yet
Fix from $1,950 2022-03-30
Job And Node Ownership HIGH 8.8
CVE-2022-28150

A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners a…

Fix: after 0.13.0
Fix from $1,950 2022-03-29
Jiratestresultreporter HIGH 8.8
CVE-2022-28136

A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect …

Fix: after 165.v817928553942
Fix from $1,950 2022-03-29
Proxmox MEDIUM 6.5
CVE-2022-28143

A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connect to an attacker-specified ho…

Fix: after 0.7.0
Fix from $1,600 2022-03-29
GitLab HIGH 8.8
CVE-2022-0427

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitra…

Fix: 14.5.4 / 14.6.4+
Fix from $1,950 2022-03-28
Sermon Browser HIGH 8.8
CVE-2022-0499

The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any…

Fix: after 0.45.22
Fix from $1,950 2022-03-28
Translate Wordpress With Gtranslate HIGH 8.8
CVE-2022-0770

The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's coo…

Fix: 2.9.9+
Fix from $1,950 2022-03-28
Osmapper MEDIUM 5.3
CVE-2021-24978

The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_aj…

Fix: after 2.1.5
Fix from $1,600 2022-03-28
Typesetter HIGH 8.8
CVE-2022-25523

TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.

Mitigation only
Fix from $1,950 2022-03-25