Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2023-46067 Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Font plugin <= 1.2.3 versions. Rocket Font after 1.2.3 Fix from $1,9502023-10-21 HIGH 8.8 CVE-2023-5690 Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2. Modoboa 2.2.2+ Fix from $1,9502023-10-20 HIGH 8.8 CVE-2023-5687 Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3. Mosparo 1.0.3+ Fix from $1,9502023-10-20 MEDIUM 5.4 CVE-2023-5534 The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to mis… Wpbot after 4.8.9 Fix from $1,6002023-10-20 HIGH 8.8 CVE-2023-5602 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… Social Media Share Buttons \& Social Sharing Icons after 2.8.5 Fix from $1,9502023-10-20 HIGH 8.8 CVE-2022-2441 The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.… Imagemagick Engine after 1.7.5 Fix from $1,9502023-10-20 HIGH 8.8 CVE-2023-4920 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect non… Bear Woocommerce Bulk Editor And Products Manager Professional after 1.1.3.3 Fix from $1,9502023-10-20 HIGH 8.8 CVE-2023-44385 The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious l… Home Assistant Companion 2023.7+ Fix from $1,9502023-10-19 CRITICAL 9.6 CVE-2023-45992 A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthentica… Ruckus Cloudpath Enrollment System after 5.12.5538 Fix from $2,3002023-10-19 HIGH 8.8 CVE-2023-42435 The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to perform actions with the permissions… Dexgate No fix yet Fix from $1,9502023-10-19 HIGH 8.8 CVE-2023-5626 Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16. Open Journal System 3.3.0-16+ Fix from $1,9502023-10-18 HIGH 8.8 CVE-2023-45901 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add. Dreamer Cms No fix yet Fix from $1,9502023-10-17 HIGH 8.8 CVE-2023-45902 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete. Dreamer Cms No fix yet Fix from $1,9502023-10-17 HIGH 8.8 CVE-2023-45903 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete. Dreamer Cms No fix yet Fix from $1,9502023-10-17 HIGH 8.8 CVE-2023-45904 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update. Dreamer Cms No fix yet Fix from $1,9502023-10-17 HIGH 8.8 CVE-2023-45905 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add. Dreamer Cms No fix yet Fix from $1,9502023-10-17 HIGH 8.8 CVE-2023-45906 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add. Dreamer Cms No fix yet Fix from $1,9502023-10-17 HIGH 8.8 CVE-2023-45907 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete. Dreamer Cms No fix yet Fix from $1,9502023-10-17 HIGH 8.8 CVE-2023-45128 Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, w… Fiber 2.50.0+ Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-45141 Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, w… Fiber 2.50.0+ Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-43118 Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 3… Exos 31.7.2 / 32.5.1.5+ Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-46087 Cross-Site Request Forgery (CSRF) vulnerability in Mahlamusa Who Hit The Page – Hit Counter plugin <= 1.4.14.3 versions. Who Hit The Page Hit Counter after 1.4.14.3 Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-45753 Cross-Site Request Forgery (CSRF) vulnerability in Gilles Dumas which template file plugin <= 4.6.0 versions. Which Template File after 4.6.0 Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-45763 Cross-Site Request Forgery (CSRF) vulnerability in Taggbox plugin <= 2.9 versions. Taggbox after 2.9 Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-45831 Cross-Site Request Forgery (CSRF) vulnerability in Pixelative, Mohsin Rafique AMP WP – Google AMP For WordPress plugin <= 1.5.15 versions. Google Amp after 1.5.15 Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-45836 Cross-Site Request Forgery (CSRF) vulnerability in XYDAC Ultimate Taxonomy Manager plugin <= 2.0 versions. Ultimate Taxonomy Manager after 2.0 Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-45748 Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch plugin <= 3.1.4 versions. Mailchimp Forms after 3.1.4 Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-45749 Cross-Site Request Forgery (CSRF) vulnerability in Alexey Golubnichenko AGP Font Awesome Collection plugin <= 3.2.4 versions. Agp Font Awesome Collection after 3.2.4 Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-45752 Cross-Site Request Forgery (CSRF) vulnerability in 10 Quality Post Gallery plugin <= 2.3.12 versions. Post Gallery after 2.3.12 Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-45639 Cross-Site Request Forgery (CSRF) vulnerability in Codex-m Sort SearchResult By Title plugin <= 10.0 versions. Sort Searchresult By Title after 10.0 Fix from $1,9502023-10-16