Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Openclaw HIGH 7.1
CVE-2026-26317

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without expl…

Fix: 2026.2.14+
Fix from $1,950 2026-02-19
Unclassified MEDIUM 5.4
CVE-2026-27050

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress RealPress realpress allows Cross Site Request Forgery.This issue affects RealPress: from…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 5.4
CVE-2026-25422

Cross-Site Request Forgery (CSRF) vulnerability in Themes4WP Popularis Extra popularis-extra allows Cross Site Request Forgery.This issue affects Pop…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 5.4
CVE-2026-25337

Cross-Site Request Forgery (CSRF) vulnerability in wpcoachify Coachify coachify allows Cross Site Request Forgery.This issue affects Coachify: from n…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 5.4
CVE-2026-25322

Cross-Site Request Forgery (CSRF) vulnerability in PublishPress PublishPress Revisions revisionary allows Cross Site Request Forgery.This issue affec…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified HIGH 8.8
CVE-2025-12821

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is due to missing or incorrect …

Mitigation only
Fix from $1,950 2026-02-19
Unclassified HIGH 8.2
CVE-2019-25359

SD.NET RIM versions before 4.7.3c contain a SQL injection vulnerability that allows attackers to inject malicious SQL statements through POST paramet…

No fix yet
Fix from $1,950 2026-02-18
Hospital Management System MEDIUM 6.5
CVE-2025-70062

PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fai…

No fix yet
Fix from $1,600 2026-02-18
Db2 Recovery Expert MEDIUM 6.5
CVE-2025-27904

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to cross-site request forgery w…

Patch available
Fix from $1,600 2026-02-17
Concert MEDIUM 6.5
CVE-2025-36018

IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an attacker to execute malicious an…

Fix: 2.2.0+
Fix from $1,600 2026-02-17
Fastgpt MEDIUM 5.4
CVE-2026-26075

FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisiti…

Fix: 4.14.7+
Fix from $1,600 2026-02-12
Unclassified CRITICAL 9.0
CVE-2025-69634

Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.…

Mitigation only
Fix from $2,300 2026-02-12
Avideo HIGH 8.8
CVE-2020-37158

AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password reco…

No fix yet
Fix from $1,950 2026-02-11
Chrome MEDIUM 6.5
CVE-2026-2317

Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted H…

Fix: 145.0.7632.45+
Fix from $1,600 2026-02-11
Kanboard HIGH 8.0
CVE-2026-24885

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in t…

Fix: 1.2.50+
Fix from $1,950 2026-02-10
Placipy HIGH 8.8
CVE-2026-25812

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests …

Mitigation only
Fix from $1,950 2026-02-09
Fast\/tools MEDIUM 5.4
CVE-2025-66595

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product is vulnerable to Cross-Site Request Forgery (…

Mitigation only
Fix from $1,600 2026-02-09
Unclassified MEDIUM 5.3
CVE-2020-37106

Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user account roles without authen…

No fix yet
Fix from $1,600 2026-02-07
Unclassified MEDIUM 5.3
CVE-2020-37144

Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a craft…

No fix yet
Fix from $1,600 2026-02-05
Ew 7438rpn Mini Firmware HIGH 8.8
CVE-2020-37149

Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authen…

No fix yet
Fix from $1,950 2026-02-05
Axigen Mail Server HIGH 8.8
CVE-2025-68722

Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface thro…

Fix: 10.5.57 / 10.6.26+
Fix from $1,950 2026-02-05
Qwik MEDIUM 5.9
CVE-2026-25151

Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP r…

Fix: 1.19.0+
Fix from $1,600 2026-02-03
Qwik HIGH 7.1
CVE-2026-25155

Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect p…

Fix: 1.12.0+
Fix from $1,950 2026-02-03
Unclassified MEDIUM 5.3
CVE-2020-37091

Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authen…

No fix yet
Fix from $1,600 2026-02-03
Ac7 Firmware MEDIUM 6.5
CVE-2026-24434

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management …

Fix: after 03.03.03.01
Fix from $1,600 2026-02-03
Open Eclass Platform MEDIUM 6.5
CVE-2026-24666

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Cross-Site Request Forgery …

Fix: 4.2+
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.4
CVE-2026-25024

Cross-Site Request Forgery (CSRF) vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Cross Site Request Forgery.This issue af…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.4
CVE-2026-24986

Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Req…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.4
CVE-2026-1447

The Mail Mint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19.2. This is due to missing n…

Mitigation only
Fix from $1,600 2026-02-03
Polarlearn HIGH 8.1
CVE-2026-25221

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, the OAuth 2.0 implementation for GitHub and Google login provi…

Patch available
Fix from $1,950 2026-02-02