Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.1
CVE-2024-51636

Cross-Site Request Forgery (CSRF) vulnerability in Z.com byGMO GMO Social Connection gmo-social-connection allows Cross-Site Scripting (XSS).This iss…

Mitigation only
Fix from $1,950 2024-11-19
Unclassified HIGH 7.1
CVE-2024-51631

Cross-Site Request Forgery (CSRF) vulnerability in Md Eftakhairul Islam Sticky Social Bar sticky-social-bar allows Cross Site Request Forgery.This is…

Mitigation only
Fix from $1,950 2024-11-19
Unclassified HIGH 7.1
CVE-2024-51632

Cross-Site Request Forgery (CSRF) vulnerability in Sam Hoe SH Slideshow sh-slideshow allows Stored XSS.This issue affects SH Slideshow: from n/a thro…

Mitigation only
Fix from $1,950 2024-11-19
Unclassified HIGH 7.1
CVE-2024-50534

Cross-Site Request Forgery (CSRF) vulnerability in techdabang World Prayer Time world-prayer-time allows Stored XSS.This issue affects World Prayer T…

No fix yet
Fix from $1,950 2024-11-19
Unclassified HIGH 7.1
CVE-2024-50533

Cross-Site Request Forgery (CSRF) vulnerability in David Garcia Domain Sharding domain-sharding allows Stored XSS.This issue affects Domain Sharding:…

Mitigation only
Fix from $1,950 2024-11-19
Wp Login Customizer MEDIUM 6.1
CVE-2024-52424

Cross-Site Request Forgery (CSRF) vulnerability in sureshdsk wp-login customizer wp-login-customizer allows Stored XSS.This issue affects wp-login cu…

Mitigation only
Fix from $1,600 2024-11-18
Ofbiz HIGH 8.8
CVE-2024-48962

Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a…

Fix: 18.12.17+
Fix from $1,950 2024-11-18
Unclassified HIGH 8.8
CVE-2024-52415

Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects S…

Mitigation only
Fix from $1,950 2024-11-16
Unclassified MEDIUM 5.3
CVE-2024-11118

The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to miss…

Mitigation only
Fix from $1,600 2024-11-16
Telepresence Video Communication Server HIGH 7.4
CVE-2022-20853

A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to co…

Mitigation only
Fix from $1,950 2024-11-15
Wallabag MEDIUM 6.5
CVE-2023-0737

wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /…

Patch available
Fix from $1,600 2024-11-15
Unclassified HIGH 7.1
CVE-2024-51658

Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.This issue affects WP Course Man…

Mitigation only
Fix from $1,950 2024-11-14
Unclassified HIGH 7.1
CVE-2024-51659

Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XSS.This issue affects Twitter …

Mitigation only
Fix from $1,950 2024-11-14
Appointmind MEDIUM 6.1
CVE-2024-51679

Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue affects Appointmind: from n/a th…

Fix: 4.1.0+
Fix from $1,600 2024-11-14
Unclassified HIGH 7.1
CVE-2024-51684

Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issue affects W3P SEO: from n/a t…

Mitigation only
Fix from $1,950 2024-11-14
Unclassified HIGH 7.1
CVE-2024-51687

Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This issue affects Platform.ly Offic…

Mitigation only
Fix from $1,950 2024-11-14
Unclassified HIGH 7.1
CVE-2024-51688

Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verification allows Stored XSS.This …

Mitigation only
Fix from $1,950 2024-11-14
Appspace MEDIUM 6.5
CVE-2021-27704

Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.

Mitigation only
Fix from $1,600 2024-11-12
Ampache HIGH 8.1
CVE-2024-51484

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR…

No fix yet
Fix from $1,950 2024-11-11
Ampache HIGH 8.1
CVE-2024-51485

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR…

No fix yet
Fix from $1,950 2024-11-11
Ampache HIGH 8.1
CVE-2024-51487

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR…

No fix yet
Fix from $1,950 2024-11-11
Ampache MEDIUM 5.4
CVE-2024-51488

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate C…

No fix yet
Fix from $1,600 2024-11-11
Ampache MEDIUM 5.4
CVE-2024-51489

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate C…

No fix yet
Fix from $1,600 2024-11-11
Unclassified HIGH 7.1
CVE-2024-51630

Cross-Site Request Forgery (CSRF) vulnerability in Lars Schenk Responsive Flickr Gallery responsive-flickr-gallery allows Stored XSS.This issue affec…

Mitigation only
Fix from $1,950 2024-11-09
Unclassified HIGH 7.1
CVE-2024-51647

Cross-Site Request Forgery (CSRF) vulnerability in Chaser324 Featured Posts Scroll allows Stored XSS.This issue affects Featured Posts Scroll: from n…

Mitigation only
Fix from $1,950 2024-11-09
Itop HIGH 8.8
CVE-2024-52002

Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerabilit…

Fix: 3.2.0+
Fix from $1,950 2024-11-08
Dingfanzu Cms CRITICAL 9.3
CVE-2024-50966

dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin.

No fix yet
Fix from $2,300 2024-11-08
Unclassified HIGH 8.8
CVE-2019-20460

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tokens or other mechanisms for v…

Mitigation only
Fix from $1,950 2024-11-07
Svakom Siime Eye Firmware HIGH 8.0
CVE-2020-11919

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection.

No fix yet
Fix from $1,950 2024-11-07
Jatos HIGH 8.4
CVE-2024-51381

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creat…

No fix yet
Fix from $1,950 2024-11-05