Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 8.8
CVE-2026-15212

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_S…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.1
CVE-2026-65540

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65536

Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.1
CVE-2026-65539

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-65512

Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery.…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.1
CVE-2026-65488

Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.6
CVE-2026-65471

Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.

Mitigation only
Fix from $2,300 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-65464

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-61981

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified CRITICAL 9.6
CVE-2026-57784

Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 8.8
CVE-2026-57785

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.

Mitigation only
Fix from $1,950 2026-07-23
Unclassified HIGH 7.1
CVE-2026-57626

Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 8.1
CVE-2026-65757

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose …

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 8.8
CVE-2026-64876

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consiste…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-64871

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not …

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 8.8
CVE-2026-63684

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Lab…

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 8.8
CVE-2026-64791

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and i…

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 8.0
CVE-2026-63265

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged …

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 8.8
CVE-2026-63280

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration…

No fix yet
Fix from $1,950 2026-07-22
Work In Process MEDIUM 5.4
CVE-2026-62563

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecte…

Fix: after 12.2.15
Fix from $1,600 2026-07-21
E Business Suite MEDIUM 6.1
CVE-2026-62487

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a…

Fix: after 12.2.15
Fix from $1,600 2026-07-21
E Business Suite HIGH 7.1
CVE-2026-62443

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a…

Fix: after 12.2.15
Fix from $1,950 2026-07-21
Human Resources Management System MEDIUM 5.4
CVE-2026-61253

Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Payroll Japanese). Supported versions that are aff…

Fix: after 12.2.15
Fix from $1,600 2026-07-21
Security Service MEDIUM 6.4
CVE-2026-61217

Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affecte…

No fix yet
Fix from $1,600 2026-07-21
Peoplesoft Enterprise Fin Program Management CRITICAL 9.0
CVE-2026-61204

Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported ve…

No fix yet
Fix from $2,300 2026-07-21
Commerce Platform HIGH 7.6
CVE-2026-61132

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is a…

No fix yet
Fix from $1,950 2026-07-21
E Business Suite HIGH 8.2
CVE-2026-61101

Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions th…

Fix: after 12.2.15
Fix from $1,950 2026-07-21
Banking Trade Finance Process Management CRITICAL 9.6
CVE-2026-61097

Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supporte…

Mitigation only
Fix from $2,300 2026-07-21
Mysql Connectors MEDIUM 6.5
CVE-2026-61082

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily…

No fix yet
Fix from $1,600 2026-07-21
Flow Manufacturing MEDIUM 5.4
CVE-2026-60962

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affe…

No fix yet
Fix from $1,600 2026-07-21