Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Flycms HIGH 8.8
CVE-2024-22568

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.

No fix yet
Fix from $1,950 2024-01-18
Flycms HIGH 8.8
CVE-2024-22591

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.

No fix yet
Fix from $1,950 2024-01-18
Flycms HIGH 8.8
CVE-2024-22592

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update

No fix yet
Fix from $1,950 2024-01-18
Flycms HIGH 8.8
CVE-2024-22593

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save

No fix yet
Fix from $1,950 2024-01-18
Pyload Ng HIGH 8.8
CVE-2024-22416

pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. Since t…

Fix: 0.5.0b3.dev78+
Fix from $1,950 2024-01-18
Stupid Simple Cms HIGH 8.8
CVE-2024-22715

Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.

Fix: after 1.2.4
Fix from $1,950 2024-01-17
Cardoza 3d Tag Cloud HIGH 8.8
CVE-2022-41990

Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8.

Fix: after 3.8
Fix from $1,950 2024-01-17
Wp Discord Invite MEDIUM 6.5
CVE-2023-5006

The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker t…

Fix: 2.5.1+
Fix from $1,600 2024-01-17
Knowledge Management MEDIUM 6.1
CVE-2024-20940

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Create, Update, Authoring Flow). Supported versions …

Fix: after 12.2.13
Fix from $1,600 2024-01-16
Complex Maintenance\, Repair\, And Overhaul MEDIUM 6.1
CVE-2024-20942

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: LOV). Supported versions that are a…

Patch available
Fix from $1,600 2024-01-16
Isupport MEDIUM 5.4
CVE-2024-20944

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 1…

Fix: after 12.2.13
Fix from $1,600 2024-01-16
Installed Base MEDIUM 6.1
CVE-2024-20934

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are aff…

Fix: after 12.2.13
Fix from $1,600 2024-01-16
Voting Record MEDIUM 5.4
CVE-2023-7083

The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Fix: after 2.0
Fix from $1,600 2024-01-16
3dprint HIGH 8.1
CVE-2022-3899

The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plug…

Fix: 3.5.6.9+
Fix from $1,950 2024-01-16
Userplus MEDIUM 6.5
CVE-2023-0824

The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as esc…

Fix: after 2.0
Fix from $1,600 2024-01-16
Wp Fastest Cache MEDIUM 6.1
CVE-2021-24870

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and es…

Fix: 0.9.5+
Fix from $1,600 2024-01-16
Wp Invoice MEDIUM 6.1
CVE-2022-1617

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as es…

Fix: after 4.3.1
Fix from $1,600 2024-01-16
Coru Lfmember MEDIUM 6.1
CVE-2022-1618

The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as esc…

Fix: after 1.0.2
Fix from $1,600 2024-01-16
Wic1200 Firmware HIGH 8.0
CVE-2024-0555

A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user int…

Mitigation only
Fix from $1,950 2024-01-16
Rompager HIGH 8.8
CVE-2024-0522

A vulnerability was found in Allegro RomPager 4.01. It has been classified as problematic. Affected is an unknown function of the file usertable.htm?…

Mitigation only
Fix from $1,950 2024-01-14
Archive Storage Manager HIGH 8.8
CVE-2023-51063

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability …

No fix yet
Fix from $1,950 2024-01-13
Verydows HIGH 8.8
CVE-2023-51949

Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller

No fix yet
Fix from $1,950 2024-01-12
Givewp MEDIUM 5.4
CVE-2023-4247

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incor…

Fix: after 2.33.3
Fix from $1,600 2024-01-11
Wp Register Profile With Shortcode HIGH 8.8
CVE-2023-5448

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This…

Fix: after 3.5.9
Fix from $1,950 2024-01-11
Fedora MEDIUM 6.5
CVE-2023-5455

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to tri…

Mitigation only
Fix from $1,600 2024-01-10
Nexo Os HIGH 8.1
CVE-2023-48258

The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session.

Fix: after 1500-sp2
Fix from $1,950 2024-01-10
S Notify MEDIUM 5.4
CVE-2023-50932

An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S…

Fix: 4.0.2+
Fix from $1,600 2024-01-09
S Notify MEDIUM 5.4
CVE-2023-50931

An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/…

Fix: 2.0.1+
Fix from $1,600 2024-01-09
S Notify HIGH 7.1
CVE-2023-50930

An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notif…

Fix: 4.0.2+
Fix from $1,950 2024-01-09
Metform Elementor Contact Form Builder MEDIUM 5.4
CVE-2023-6788

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8…

Fix: after 3.8.1
Fix from $1,600 2024-01-09