Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
GitLab HIGH 8.0
CVE-2022-0154

An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all v…

Fix: 14.4.5 / 14.5.3+
Fix from $1,950 2022-01-18
Login\/signup Popup HIGH 8.8
CVE-2022-0215

The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable …

Fix: after 2.5.1
Fix from $1,950 2022-01-18
Crisp HIGH 8.8
CVE-2021-43353

The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page f…

Fix: 0.32+
Fix from $1,950 2022-01-18
Calibre Web HIGH 8.8
CVE-2021-4164

calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 0.6.15+
Fix from $1,950 2022-01-17
Quiz And Survey Master HIGH 8.8
CVE-2022-0180

Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authenticati…

Fix: 7.3.7+
Fix from $1,950 2022-01-17
Live Helper Chat MEDIUM 6.5
CVE-2022-0231

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: after 3.91
Fix from $1,600 2022-01-14
Php Everywhere HIGH 8.8
CVE-2021-23227

Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions.

Fix: after 2.0.2
Fix from $1,950 2022-01-13
Fedora HIGH 8.8
CVE-2022-0196

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 10.8.0+
Fix from $1,950 2022-01-13
Fedora HIGH 8.8
CVE-2022-0197

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 10.8.0+
Fix from $1,950 2022-01-13
Bitbucket Branch Source HIGH 7.1
CVE-2022-20619

A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect…

Fix: after 2.9.10
Fix from $1,950 2022-01-12
Batch Task MEDIUM 5.4
CVE-2022-23115

Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Overall/Read access to retrieve…

Fix: after 1.19
Fix from $1,600 2022-01-12
Suitecrm HIGH 8.8
CVE-2021-41597

SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included …

Fix: 7.10.35 / 7.12.2+
Fix from $1,950 2022-01-12
Comos HIGH 8.8
CVE-2021-37198

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web …

Fix: 10.3.3.3+
Fix from $1,950 2022-01-11
Modal Window HIGH 8.8
CVE-2021-25051

The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well …

Fix: 5.2.2+
Fix from $1,950 2022-01-10
Button Generator HIGH 8.8
CVE-2021-25052

The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as w…

Fix: 2.3.3+
Fix from $1,950 2022-01-10
Wp Coder HIGH 8.8
CVE-2021-25053

The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as w…

Fix: 2.5.2+
Fix from $1,950 2022-01-10
Capabilities CRITICAL 9.8
CVE-2021-25032EPSS 7%

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation …

Fix: 2.3.1+
Fix from $2,300 2022-01-10
Mediawiki HIGH 8.8
CVE-2021-46147

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF.

Fix: 1.35.5 / 1.36.3+
Fix from $1,950 2022-01-10
Ultimaker S3 Firmware HIGH 8.8
CVE-2021-34086

In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver ho…

Fix: after 6.3
Fix from $1,950 2022-01-10
Tew 827dru Firmware HIGH 8.8
CVE-2021-20165

Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigati…

No fix yet
Fix from $1,950 2021-12-30
Wrd12en Firmware MEDIUM 6.5
CVE-2020-29292

iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP ad…

Mitigation only
Fix from $1,600 2021-12-30
Damicms HIGH 8.8
CVE-2020-21236

A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtai…

No fix yet
Fix from $1,950 2021-12-27
Qibosoft HIGH 8.8
CVE-2020-20945

A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator…

No fix yet
Fix from $1,950 2021-12-27
Wp Rss Aggregator MEDIUM 5.4
CVE-2021-24988

The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which…

Fix: 4.19.3+
Fix from $1,600 2021-12-27
Showdoc HIGH 8.8
CVE-2021-4168

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 2.9.15+
Fix from $1,950 2021-12-26
Rockoa HIGH 8.0
CVE-2020-20593

A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.

No fix yet
Fix from $1,950 2021-12-22
Opms MEDIUM 6.5
CVE-2020-20595

A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.

No fix yet
Fix from $1,600 2021-12-22
Contact Form 7 Database Addon HIGH 8.8
CVE-2021-36886

Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9).

Fix: 1.2.6.1+
Fix from $1,950 2021-12-22
Online Book Store Project In Php MEDIUM 6.5
CVE-2021-43156

In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.

No fix yet
Fix from $1,600 2021-12-22
Directorist HIGH 7.5
CVE-2021-24981

The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell upl…

Fix: 7.0.6.2+
Fix from $1,950 2021-12-21