Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Sensor Net Connect Firmware V2 HIGH 8.3
CVE-2024-3083

A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileg…

Mitigation only
Fix from $1,950 2024-07-31
Html Forms MEDIUM 6.5
CVE-2024-6412

The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Fix: 1.3.34+
Fix from $1,600 2024-07-31
Aspera Orchestrator MEDIUM 6.5
CVE-2023-38001

IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…

Mitigation only
Fix from $1,600 2024-07-30
Medicine Tracker System HIGH 8.8
CVE-2024-7226

A vulnerability was found in SourceCodester Medicine Tracker System 1.0. It has been declared as problematic. This vulnerability affects unknown code…

No fix yet
Fix from $1,950 2024-07-30
Pardakht Delkhah MEDIUM 6.5
CVE-2024-6230

The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers…

Fix: 2.9.9+
Fix from $1,600 2024-07-30
Ipados HIGH 7.5
CVE-2024-40815

A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, …

Fix: 10.6 / 13.6.8+
Fix from $1,950 2024-07-29
Wp Affiliate Platform MEDIUM 5.5
CVE-2024-5285

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to ma…

Fix: 6.5.2+
Fix from $1,600 2024-07-29
School Fees Payment System HIGH 8.8
CVE-2024-7169

A vulnerability classified as problematic has been found in SourceCodester School Fees Payment System 1.0. This affects an unknown part of the file /…

No fix yet
Fix from $1,950 2024-07-28
Seacms MEDIUM 6.5
CVE-2024-7161

A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of the file /member.ph…

No fix yet
Fix from $1,600 2024-07-28
Master Slider MEDIUM 6.5
CVE-2024-6490

During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate…

Fix: 3.10.0+
Fix from $1,600 2024-07-26
Spina HIGH 8.8
CVE-2024-7106

A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admi…

Fix: after 2.18.0
Fix from $1,950 2024-07-25
Litespeed Cache MEDIUM 5.4
CVE-2024-3246

The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to mi…

Fix: 6.3+
Fix from $1,600 2024-07-24
Social Auto Poster MEDIUM 6.5
CVE-2024-6751

The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to miss…

Fix: 5.3.15+
Fix from $1,600 2024-07-24
Pz Frontend Manager HIGH 8.8
CVE-2024-6244

The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users p…

Fix: 1.0.6+
Fix from $1,950 2024-07-22
Community Events MEDIUM 5.4
CVE-2024-6271

The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged…

Fix: 1.5+
Fix from $1,600 2024-07-22
Spina HIGH 8.8
CVE-2024-41602

Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privileges via a crafted URL

Mitigation only
Fix from $1,950 2024-07-19
Spina CRITICAL 9.6
CVE-2024-41603

Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.

Mitigation only
Fix from $2,300 2024-07-19
Artplacer Widget HIGH 7.5
CVE-2023-7269

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which c…

Fix: after 2.21.1
Fix from $1,950 2024-07-19
Online Shopping Portal MEDIUM 6.1
CVE-2024-39090

The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cr…

No fix yet
Fix from $1,600 2024-07-18
Cooked HIGH 8.8
CVE-2024-39678

Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.1…

Fix: 1.8.0+
Fix from $1,950 2024-07-18
Cooked HIGH 8.8
CVE-2024-39679

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and in…

Fix: 1.8.0+
Fix from $1,950 2024-07-18
Cooked HIGH 8.8
CVE-2024-39680

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and in…

Fix: 1.8.0+
Fix from $1,950 2024-07-18
Cooked HIGH 8.8
CVE-2024-39681

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and in…

Fix: 1.8.0+
Fix from $1,950 2024-07-18
Unclassified HIGH 8.8
CVE-2024-40119

Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the pa…

Mitigation only
Fix from $1,950 2024-07-17
Enterprise Server MEDIUM 6.5
CVE-2024-5815

A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect …

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Wp Estore HIGH 8.8
CVE-2024-6075

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged i…

Fix: 8.5.5+
Fix from $1,950 2024-07-15
Wp Emember MEDIUM 6.8
CVE-2024-5077

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could a…

Fix: 10.6.6+
Fix from $1,600 2024-07-13
Cm E Mail Blacklist HIGH 8.1
CVE-2024-5167

The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the bla…

Fix: 1.4.9+
Fix from $1,950 2024-07-13
Wp Affiliate Platform MEDIUM 6.8
CVE-2024-5284

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi…

Fix: 6.5.1+
Fix from $1,600 2024-07-13
Wp Affiliate Platform HIGH 7.1
CVE-2024-5287

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to …

Fix: 6.5.1+
Fix from $1,950 2024-07-13