Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Publiccms HIGH 8.8
CVE-2025-65840

PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.

No fix yet
Fix from $1,950 2025-12-01
Diris M 70 Firmware HIGH 8.8
CVE-2024-53684

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTT…

Mitigation only
Fix from $1,950 2025-12-01
Unclassified MEDIUM 5.4
CVE-2025-13296

Cross-Site Request Forgery (CSRF) vulnerability in Tekrom Technology Inc. T-Soft E-Commerce allows Cross Site Request Forgery. This issue affects T-…

Mitigation only
Fix from $1,600 2025-12-01
Scada Lts HIGH 8.8
CVE-2025-13790

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The…

Fix: after 2.7.8.1
Fix from $1,950 2025-11-30
Kiteworks Managed File Transfer MEDIUM 6.8
CVE-2025-53897

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain ac…

Fix: 9.1.0+
Fix from $1,600 2025-11-29
Unica MEDIUM 5.5
CVE-2025-51733

Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

No fix yet
Fix from $1,600 2025-11-28
Ray HIGH 8.8
CVE-2025-62593 KEV

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerabi…

Fix: 2.52.0+
Fix from $1,950 2025-11-26
Unclassified HIGH 8.6
CVE-2025-12061

The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users…

Mitigation only
Fix from $1,950 2025-11-26
Eve X1 Server Firmware CRITICAL 9.6
CVE-2025-60739

Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 …

No fix yet
Fix from $2,300 2025-11-25
Snc Cx600w Firmware MEDIUM 6.5
CVE-2025-62497

Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a specially crafted webpage while logge…

Fix: 2.8.0+
Fix from $1,600 2025-11-25
Smartlife HIGH 8.8
CVE-2025-56400

Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Sma…

Fix: 6.5.0+
Fix from $1,950 2025-11-24
Pro Convert Hdmi 4k Plus Firmware MEDIUM 5.7
CVE-2025-63952

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create a…

No fix yet
Fix from $1,600 2025-11-24
Ultra Encode Hdmi Firmware MEDIUM 6.5
CVE-2025-63953

A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create a…

No fix yet
Fix from $1,600 2025-11-24
Langfuse MEDIUM 6.5
CVE-2025-65107

Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in…

Fix: 2.95.12 / 3.131.0+
Fix from $1,600 2025-11-21
Unclassified HIGH 8.8
CVE-2025-11087

The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.0.1. Thi…

Mitigation only
Fix from $1,950 2025-11-21
Unclassified MEDIUM 6.1
CVE-2025-13134

The AuthorSure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or …

Mitigation only
Fix from $1,600 2025-11-21
Logstare Collector MEDIUM 6.5
CVE-2025-62687

Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be perf…

Fix: 2.4.2+
Fix from $1,600 2025-11-21
Unclassified MEDIUM 6.8
CVE-2025-62346

A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwan…

No fix yet
Fix from $1,600 2025-11-20
Unclassified MEDIUM 5.3
CVE-2025-12535

The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to th…

Mitigation only
Fix from $1,600 2025-11-19
Student Record System HIGH 7.5
CVE-2025-63955

A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to…

No fix yet
Fix from $1,950 2025-11-18
Windu Cms MEDIUM 6.5
CVE-2025-59112

Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft special website, which when visited…

Mitigation only
Fix from $1,600 2025-11-18
Windu Cms MEDIUM 6.5
CVE-2025-59114

Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft special website, which when visit…

Mitigation only
Fix from $1,600 2025-11-18
Windu Cms MEDIUM 6.5
CVE-2025-59110

Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechanism can be bypassed by using C…

Mitigation only
Fix from $1,600 2025-11-18
Api Control Plane HIGH 8.8
CVE-2025-6670

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operation…

Mitigation only
Fix from $1,950 2025-11-18
Unclassified MEDIUM 6.1
CVE-2025-12404

The Like-it plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or inc…

Mitigation only
Fix from $1,600 2025-11-18
Unclassified MEDIUM 6.1
CVE-2025-12406

The Project Honey Pot Spam Trap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is…

Mitigation only
Fix from $1,600 2025-11-18
Rumpus HIGH 8.8
CVE-2025-55057

Multiple CWE-352 Cross-Site Request Forgery (CSRF)

No fix yet
Fix from $1,950 2025-11-17
Tenderdoctransfer HIGH 8.1
CVE-2025-13282

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and prov…

Fix: 0.41.159+
Fix from $1,950 2025-11-17
Tenderdoctransfer HIGH 7.1
CVE-2025-13283

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server…

Fix: 0.41.159+
Fix from $1,950 2025-11-17
Wholesale MEDIUM 6.5
CVE-2025-13179

A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects so…

Fix: after 2025-10-16
Fix from $1,600 2025-11-14