Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.1
CVE-2024-54386

Cross-Site Request Forgery (CSRF) vulnerability in pushmonkey Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart push-monkey-des…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified CRITICAL 9.6
CVE-2024-54368

Cross-Site Request Forgery (CSRF) vulnerability in rubengarzajr GitSync git-sync allows Code Injection.This issue affects GitSync: from n/a through <…

Mitigation only
Fix from $2,300 2024-12-16
Unclassified CRITICAL 9.6
CVE-2024-54372

Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Insertify insertify allows Code Injection.This issue affects Insertify: from n/a throu…

Mitigation only
Fix from $2,300 2024-12-16
Wp Mailster HIGH 8.8
CVE-2024-54355

Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.This issue affects WP Mailster…

Fix: 1.8.17+
Fix from $1,950 2024-12-16
Online Booking \& Scheduling Calendar MEDIUM 5.4
CVE-2024-54356

Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allow…

Fix: 4.5.2+
Fix from $1,600 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54331

Cross-Site Request Forgery (CSRF) vulnerability in Micha I Plant A Tree i-plant-a-tree allows Stored XSS.This issue affects I Plant A Tree: from n/a …

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54332

Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allows Stored XSS.This issue affec…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 8.8
CVE-2024-54352

Cross-Site Request Forgery (CSRF) vulnerability in Sabri Sogrid sogrid allows Privilege Escalation.This issue affects Sogrid: from n/a through <= 1.5…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54353

Cross-Site Request Forgery (CSRF) vulnerability in wpgear Hack-Info hack-info allows Stored XSS.This issue affects Hack-Info: from n/a through <= 3.1…

Mitigation only
Fix from $1,950 2024-12-16
Tenderdoctransfer HIGH 8.1
CVE-2024-12642

TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides API…

Fix: 0.41.157+
Fix from $1,950 2024-12-16
Unclassified HIGH 8.1
CVE-2024-12643

The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs …

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-12644

The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for com…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified MEDIUM 6.5
CVE-2024-12645

The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local web server and provides APIs f…

Mitigation only
Fix from $1,600 2024-12-16
Unclassified HIGH 8.1
CVE-2024-12646

The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified MEDIUM 6.1
CVE-2024-12555

The SIP Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing…

Mitigation only
Fix from $1,600 2024-12-14
Itop CRITICAL 9.6
CVE-2024-54139

Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scrip…

Fix: 2.7.11 / 3.1.2+
Fix from $2,300 2024-12-13
Unclassified HIGH 7.1
CVE-2024-54351

Cross-Site Request Forgery (CSRF) vulnerability in Thomas K Landis Fancy Roller Scroller fancy-roller-scroller allows Stored XSS.This issue affects F…

Mitigation only
Fix from $1,950 2024-12-13
Unclassified HIGH 7.1
CVE-2024-54337

Cross-Site Request Forgery (CSRF) vulnerability in DevriX DX Dark Site devrix-dark-site allows Stored XSS.This issue affects DX Dark Site: from n/a t…

Mitigation only
Fix from $1,950 2024-12-13
Unclassified HIGH 8.8
CVE-2024-54248

Cross-Site Request Forgery (CSRF) vulnerability in eewee eewee admin custom eewee-admincustom allows Privilege Escalation.This issue affects eewee ad…

Mitigation only
Fix from $1,950 2024-12-13
Unclassified MEDIUM 6.5
CVE-2023-41686

Cross-Site Request Forgery (CSRF) vulnerability in ilGhera Woocommerce Support System allows Cross Site Request Forgery.This issue affects Woocommerc…

Mitigation only
Fix from $1,600 2024-12-13
Unclassified MEDIUM 6.1
CVE-2024-12572

The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due …

Mitigation only
Fix from $1,600 2024-12-13
Unclassified HIGH 8.8
CVE-2024-11689

The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.29. This is due to …

Mitigation only
Fix from $1,950 2024-12-12
Unclassified MEDIUM 6.1
CVE-2024-11417

The dejure.org Vernetzungsfunktion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.97.5. Thi…

Mitigation only
Fix from $1,600 2024-12-12
Unclassified MEDIUM 6.1
CVE-2024-11419

The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missin…

Mitigation only
Fix from $1,600 2024-12-12
Unclassified MEDIUM 6.3
CVE-2024-28141

The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on th…

Mitigation only
Fix from $1,600 2024-12-11
Unclassified MEDIUM 6.1
CVE-2024-12004

The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. Thi…

Mitigation only
Fix from $1,600 2024-12-11
Unclassified HIGH 8.8
CVE-2024-55500

Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution o…

Patch available
Fix from $1,950 2024-12-10
Unclassified HIGH 8.8
CVE-2020-28398

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX …

Mitigation only
Fix from $1,950 2024-12-10
Unclassified HIGH 7.1
CVE-2024-54226

Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This issue affects Country Blocker…

Mitigation only
Fix from $1,950 2024-12-09
Variation Swatches MEDIUM 5.4
CVE-2023-28688

Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk TH Variation Swatches allows Cross Site Request Forgery.This issue affects TH Variation …

Fix: 1.2.8+
Fix from $1,600 2024-12-09