Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Saleor MEDIUM 5.4
CVE-2024-31205

Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attac…

Fix: 3.14.64 / 3.15.39+
Fix from $1,600 2024-04-08
Unclassified MEDIUM 6.8
CVE-2023-49965

SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.

Mitigation only
Fix from $1,600 2024-04-05
Learnpress HIGH 8.8
CVE-2024-2115

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. T…

Fix: 4.0.1+
Fix from $1,950 2024-04-05
Unclassified CRITICAL 9.1
CVE-2024-27448

MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing a…

Mitigation only
Fix from $2,300 2024-04-05
Go2rtc HIGH 8.8
CVE-2024-29192

gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to Cross-Site Request Forgery. The `/api/config` endpoint allows o…

Fix: after 1.8.5
Fix from $1,950 2024-04-04
Portal For Arcgis MEDIUM 5.4
CVE-2024-25692

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthen…

Fix: after 11.1
Fix from $1,600 2024-04-04
Identity Services Engine HIGH 8.8
CVE-2024-20368

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond…

Fix: 3.1.0+
Fix from $1,950 2024-04-03
Emergency Responder MEDIUM 6.5
CVE-2024-20347

A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker…

Fix: 12.5+
Fix from $1,600 2024-04-03
Nexus Dashboard HIGH 8.8
CVE-2024-20281

A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticat…

Fix: 3.1 / 4.3+
Fix from $1,950 2024-04-03
Woocommerce Cart Abandonment Recovery MEDIUM 6.8
CVE-2024-2322

The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to…

Fix: 1.2.27+
Fix from $1,600 2024-04-03
Unclassified HIGH 7.1
CVE-2024-31105

Cross-Site Request Forgery (CSRF) vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a throu…

Mitigation only
Fix from $1,950 2024-04-02
Unclassified HIGH 7.1
CVE-2024-31109

Cross-Site Request Forgery (CSRF) vulnerability in Toastie Studio Woocommerce Social Media Share Buttons allows Stored XSS.This issue affects Woocomm…

Mitigation only
Fix from $1,950 2024-04-02
Dedecms HIGH 8.8
CVE-2024-30965

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.

Patch available
Fix from $1,950 2024-04-02
Dedecms MEDIUM 5.5
CVE-2024-30946

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.

No fix yet
Fix from $1,600 2024-04-02
Localai MEDIUM 6.5
CVE-2024-3135

A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when…

Fix: 2.17.0+
Fix from $1,600 2024-04-01
Unclassified MEDIUM 5.4
CVE-2024-31100

Cross-Site Request Forgery (CSRF) vulnerability in Festi-Team Popup Cart Lite for WooCommerce.This issue affects Popup Cart Lite for WooCommerce: fro…

Mitigation only
Fix from $1,600 2024-03-31
Lollms Web Ui HIGH 8.8
CVE-2024-1522

A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim'…

Fix: after 9.2
Fix from $1,950 2024-03-30
Husky Products Filter Professional For Woocommerce HIGH 8.8
CVE-2024-30462

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Prod…

Fix: 1.3.5.2+
Fix from $1,950 2024-03-29
Wp Sms HIGH 8.8
CVE-2024-30454

Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.

Fix: 6.6.3+
Fix from $1,950 2024-03-29
Unclassified MEDIUM 5.4
CVE-2024-30521

Cross-Site Request Forgery (CSRF) vulnerability in Landingi Landingi Landing Pages.This issue affects Landingi Landing Pages: from n/a through 3.1.1.

No fix yet
Fix from $1,600 2024-03-29
Simple Revisions Delete HIGH 8.8
CVE-2024-30482

Cross-Site Request Forgery (CSRF) vulnerability in Brice CAPOBIANCO Simple Revisions Delete.This issue affects Simple Revisions Delete: from n/a thro…

Fix: after 1.5.3
Fix from $1,950 2024-03-29
Wordpress Currency Switcher HIGH 8.8
CVE-2024-30456

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.

Fix: 1.2.0.2+
Fix from $1,950 2024-03-29
Wordpress Meta Data And Taxonomies Filter HIGH 8.8
CVE-2024-30457

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data…

Fix: 1.3.3.2+
Fix from $1,950 2024-03-29
Fox Currency Switcher Professional For Woocommerce HIGH 8.8
CVE-2024-30458

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency S…

Fix: 1.4.1.8+
Fix from $1,950 2024-03-29
Wp Eggdrop MEDIUM 5.4
CVE-2024-2969

The WP-Eggdrop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or …

Mitigation only
Fix from $1,600 2024-03-29
Unclassified MEDIUM 6.1
CVE-2022-45850

Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro allows Stored XSS.This issue affects Image Map Pro: from n/a before 5.6.9.

Mitigation only
Fix from $1,600 2024-03-28
Jupyterhub MEDIUM 6.1
CVE-2024-28233

JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achiev…

Fix: 4.1.0+
Fix from $1,600 2024-03-27
Unclassified HIGH 7.1
CVE-2024-29773

Cross-Site Request Forgery (CSRF) vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint allows Cross-Site Scripting (XSS).This issue affects B…

Mitigation only
Fix from $1,950 2024-03-27
Fusion Builder HIGH 8.8
CVE-2023-39311

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.

Fix: after 3.11.1
Fix from $1,950 2024-03-27
Stripe Payment Gateway HIGH 8.8
CVE-2023-44999

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gatew…

Fix: after 7.6.0
Fix from $1,950 2024-03-27