Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Cloudstack HIGH 8.8
CVE-2024-45693

Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of t…

Fix: 4.18.2.4 / 4.19.1.2+
Fix from $1,950 2024-10-16
File Manager HIGH 8.8
CVE-2024-8507

The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to mis…

Fix: 8.3.10+
Fix from $1,950 2024-10-16
Unclassified HIGH 8.3
CVE-2020-36839

The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.99. This is due to missing or…

Mitigation only
Fix from $1,950 2024-10-16
Wp Fastest Cache HIGH 8.0
CVE-2020-36836

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a la…

Fix: 0.9.0.3+
Fix from $1,950 2024-10-16
Watson Studio Local HIGH 8.8
CVE-2024-49340

IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…

Mitigation only
Fix from $1,950 2024-10-16
Peoplesoft Enterprise Peopletools MEDIUM 6.1
CVE-2024-21202

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are af…

Mitigation only
Fix from $1,600 2024-10-15
Codeigniter HIGH 7.5
CVE-2024-41344

A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

No fix yet
Fix from $1,950 2024-10-15
Hono MEDIUM 5.9
CVE-2024-48913

Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Ty…

Fix: 4.6.5+
Fix from $1,600 2024-10-15
User Registration \& Login And User Management System MEDIUM 5.5
CVE-2024-48278

Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.

No fix yet
Fix from $1,600 2024-10-15
Lollms Web Ui HIGH 7.1
CVE-2024-6959

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends…

No fix yet
Fix from $1,950 2024-10-13
Unclassified MEDIUM 6.1
CVE-2024-9592

The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is du…

Mitigation only
Fix from $1,600 2024-10-12
Ampache MEDIUM 6.5
CVE-2024-47828

ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smart…

Fix: after 6.6.0
Fix from $1,600 2024-10-09
Unclassified HIGH 7.1
CVE-2024-44028

Cross-Site Request Forgery (CSRF) vulnerability in nicejob NiceJob nicejob allows Stored XSS.This issue affects NiceJob: from n/a through < 3.6.5.

Mitigation only
Fix from $1,950 2024-10-06
Unclassified MEDIUM 5.4
CVE-2024-47635

Cross-Site Request Forgery (CSRF) vulnerability in TinyPNG TinyPNG tiny-compress-images allows Cross Site Request Forgery.This issue affects TinyPNG:…

Mitigation only
Fix from $1,600 2024-10-05
Cargo HIGH 8.8
CVE-2024-47846

Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Me…

Patch available
Fix from $1,950 2024-10-05
Timeprovider 4100 Firmware HIGH 8.8
CVE-2024-43684

Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This iss…

Fix: 2.4.7+
Fix from $1,950 2024-10-04
Unclassified HIGH 8.6
CVE-2024-41987

The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any valid…

Mitigation only
Fix from $1,950 2024-10-03
Unclassified MEDIUM 6.8
CVE-2023-7273

Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it i…

Mitigation only
Fix from $1,600 2024-10-01
Gs 4210 24p2s Firmware HIGH 8.8
CVE-2024-8458

Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remot…

Fix: 2.305b240719 / 3.305b240802+
Fix from $1,950 2024-09-30
Adam 5630 Firmware HIGH 8.8
CVE-2024-28948

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, w…

Fix: 2.5.2+
Fix from $1,950 2024-09-27
Online Voting System MEDIUM 6.5
CVE-2024-45987

Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker…

No fix yet
Fix from $1,600 2024-09-26
Hospital Management System MEDIUM 6.3
CVE-2024-45983

A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attack…

No fix yet
Fix from $1,600 2024-09-26
Mzk Dp300n Firmware MEDIUM 6.5
CVE-2024-45372

MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the we…

Fix: after 1.04
Fix from $1,600 2024-09-26
Strawberry HIGH 8.0
CVE-2024-47082

Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as defined in the GraphQL multipar…

Fix: 0.243.0+
Fix from $1,950 2024-09-25
Use Any Font HIGH 8.8
CVE-2024-47305

Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font use-any-font allows Cross Site Request Forgery.This issue affects Use Any…

Fix: 6.3.09+
Fix from $1,950 2024-09-25
Givewp HIGH 8.8
CVE-2024-47315

Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.15.1.

Fix: 3.16.0+
Fix from $1,950 2024-09-25
Ios Xe HIGH 8.8
CVE-2024-20437

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-sit…

Mitigation only
Fix from $1,950 2024-09-25
Ios Xe MEDIUM 6.5
CVE-2024-20414

A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cr…

Mitigation only
Fix from $1,600 2024-09-25
Dingfanzu Cms MEDIUM 6.3
CVE-2024-46485

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate

No fix yet
Fix from $1,600 2024-09-25
Ba Book Everything HIGH 8.8
CVE-2024-8795

The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to …

Fix: 1.6.21+
Fix from $1,950 2024-09-24