Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Weblogic Server MEDIUM 6.1
CVE-2024-20986

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $1,600 2024-02-17
Installed Base MEDIUM 6.1
CVE-2024-20933

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are aff…

Fix: after 12.2.13
Fix from $1,600 2024-02-17
Commerce MEDIUM 6.5
CVE-2024-20718

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result …

Mitigation only
Fix from $1,600 2024-02-15
Jh Rvb1 Firmware MEDIUM 6.5
CVE-2024-23785

Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remot…

Mitigation only
Fix from $1,600 2024-02-14
Azure Active Directory MEDIUM 6.8
CVE-2024-21381

Microsoft Azure Active Directory B2C Spoofing Vulnerability

Patch available
Fix from $1,600 2024-02-13
Smtp Mail HIGH 8.8
CVE-2024-25914

Cross-Site Request Forgery (CSRF) vulnerability in Photoboxone SMTP Mail.This issue affects SMTP Mail: from n/a through 1.3.20.

Fix: after 1.3.20
Fix from $1,950 2024-02-13
\ HIGH 8.8
CVE-2023-52431

The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an…

Fix: 0.0.19+
Fix from $1,950 2024-02-13
Lastunes MEDIUM 5.4
CVE-2023-6499

The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could all…

Fix: after 3.6.1
Fix from $1,600 2024-02-12
Link Library HIGH 8.8
CVE-2024-24875

Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.

Fix: after 7.5.13
Fix from $1,950 2024-02-12
Contact Form 7 Connector HIGH 8.8
CVE-2024-24884

Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.…

Fix: after 1.2.2
Fix from $1,950 2024-02-12
Contest Gallery HIGH 8.8
CVE-2024-24887

Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Vot…

Fix: 21.2.9+
Fix from $1,950 2024-02-12
Wp Contact Form HIGH 8.8
CVE-2024-24929

Cross-Site Request Forgery (CSRF) vulnerability in Ryan Duff, Peter Westwood WP Contact Form.This issue affects WP Contact Form: from n/a through 1.6.

Fix: after 1.6
Fix from $1,950 2024-02-12
Basic Log Viewer HIGH 8.8
CVE-2024-24935

Cross-Site Request Forgery (CSRF) vulnerability in WpSimpleTools Basic Log Viewer.This issue affects Basic Log Viewer: from n/a through 1.0.4.

Fix: after 1.0.4
Fix from $1,950 2024-02-12
Flusity HIGH 8.8
CVE-2024-25417

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.

No fix yet
Fix from $1,950 2024-02-11
Flusity HIGH 8.8
CVE-2024-25418

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php.

No fix yet
Fix from $1,950 2024-02-11
Flusity HIGH 8.8
CVE-2024-25419

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.

No fix yet
Fix from $1,950 2024-02-11
Sametime HIGH 8.8
CVE-2023-50349

Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to…

Fix: 12.0.2+
Fix from $1,950 2024-02-09
Icingaweb2 Module Incubator HIGH 8.8
CVE-2024-24819

icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base…

Fix: 0.22.0+
Fix from $1,950 2024-02-09
Icinga HIGH 8.3
CVE-2024-24820

Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate …

Fix: 1.8.2 / 1.9.2+
Fix from $1,950 2024-02-09
Terminal Handler HIGH 8.8
CVE-2023-47020

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafte…

No fix yet
Fix from $1,950 2024-02-08
Expressway HIGH 8.8
CVE-2024-20254

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote at…

Fix: after 15.0
Fix from $1,950 2024-02-07
Expressway HIGH 7.1
CVE-2024-20255

A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote a…

Fix: 15.0+
Fix from $1,950 2024-02-07
Expressway HIGH 8.8
CVE-2024-20252

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote at…

Fix: after 15.0
Fix from $1,950 2024-02-07
L206 F2g Firmware HIGH 8.8
CVE-2023-38579

The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which cou…

Mitigation only
Fix from $1,950 2024-02-06
Clearml HIGH 8.8
CVE-2024-24593

A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a …

Fix: after 1.14.1
Fix from $1,950 2024-02-06
Index Now HIGH 8.8
CVE-2024-0428

The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3. This is due to missing or…

Fix: after 2.6.3
Fix from $1,950 2024-02-05
Flusity HIGH 8.8
CVE-2024-24468

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php.

No fix yet
Fix from $1,950 2024-02-05
Flusity HIGH 8.8
CVE-2024-24469

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.

No fix yet
Fix from $1,950 2024-02-05
Ledgersmb HIGH 7.5
CVE-2024-23831

LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker…

Fix: 1.10.30 / 1.11.9+
Fix from $1,950 2024-02-02
Flusity HIGH 8.8
CVE-2024-24470

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.

No fix yet
Fix from $1,950 2024-02-02