Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2023-4455 Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. Wallabag 2.6.3+ Fix from $1,6002023-08-21 MEDIUM 5.7 CVE-2023-4454 Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. Wallabag 2.6.3+ Fix from $1,6002023-08-21 HIGH 8.8 CVE-2023-40172 Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. A Cross-site request forger… Social Media Skeleton 1.0.5+ Fix from $1,9502023-08-18 MEDIUM 6.1 CVE-2023-31218 Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Man… Wolf Wordpress Posts Bulk Editor And Products Manager Professional 1.0.7+ Fix from $1,6002023-08-18 MEDIUM 6.5 CVE-2023-20221 A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauth… Video Phone 8875 Firmware 2.0+ Fix from $1,6002023-08-16 HIGH 8.8 CVE-2023-40336 A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy folders. Folders after 6.846.v23698686f0f6 Fix from $1,9502023-08-16 HIGH 8.8 CVE-2023-40341 A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specifie… Blue Ocean after 1.27.5 Fix from $1,9502023-08-16 HIGH 8.8 CVE-2020-23595 Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information … Yzmcms No fix yet Fix from $1,9502023-08-11 HIGH 8.8 CVE-2020-24922 Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitr… Xxl Job No fix yet Fix from $1,9502023-08-11 HIGH 8.8 CVE-2023-4276 The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing n… Absolute Privacy after 2.1 Fix from $1,9502023-08-10 MEDIUM 6.5 CVE-2023-4277 The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce val… Realia after 1.4.0 Fix from $1,6002023-08-10 HIGH 8.8 CVE-2023-38348 A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1. Benno Mailarchiv 2.10.2+ Fix from $1,9502023-08-09 MEDIUM 6.5 CVE-2023-38999 A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.… Opnsense 23.7+ Fix from $1,6002023-08-09 HIGH 8.8 CVE-2023-31452 A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform act… Prtg Network Monitor 23.3.86.1520+ Fix from $1,9502023-08-09 HIGH 8.8 CVE-2023-38759 Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user… Workout Manager Mitigation only Fix from $1,9502023-08-08 HIGH 8.8 CVE-2023-4047 A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerabil… Firefox 102.14 / 115.1+ Fix from $1,9502023-08-01 HIGH 8.8 CVE-2023-33534 A Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11.6 allows attackers to takeove… Zlt S10g Firmware No fix yet Fix from $1,9502023-07-31 MEDIUM 6.5 CVE-2020-21881 Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via article/admin/cont… Duxcms No fix yet Fix from $1,6002023-07-31 HIGH 8.8 CVE-2023-38512 Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream wpstream allows Cross Site Request Forgery.This issue affects WpStream: from n/a… Wpstream 4.5.5+ Fix from $1,9502023-07-27 MEDIUM 6.5 CVE-2023-3414 A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited success… Servicenow Devops 1.38.1+ Fix from $1,6002023-07-26 MEDIUM 5.4 CVE-2023-39153 A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into log… Gitlab Authentication after 1.17.1 Fix from $1,6002023-07-26 MEDIUM 5.3 CVE-2023-39156 A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete previously created Bazaar SCM … Bazaar after 1.22 Fix from $1,6002023-07-26 HIGH 8.8 CVE-2022-43710 Interactive Forms (IAF) in GX Software XperienCentral versions 10.31.0 until 10.33.0 was vulnerable to cross site request forgery (CSRF) because the … Xperiencentral after 10.33.0 Fix from $1,9502023-07-26 HIGH 8.8 CVE-2022-30280 /SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even adm… Netact No fix yet Fix from $1,9502023-07-24 HIGH 8.8 CVE-2023-3841 A vulnerability has been found in NxFilter 4.3.2.5 and classified as problematic. This vulnerability affects unknown code of the file user.jsp. The m… Nxfilter Mitigation only Fix from $1,9502023-07-23 HIGH 8.8 CVE-2023-37650 A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands. Cockpit after 2.5.2 Fix from $1,9502023-07-20 MEDIUM 6.5 CVE-2023-28023 A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to a… Bigfix Webui after 44 Fix from $1,6002023-07-18 HIGH 8.8 CVE-2023-37386 Cross-Site Request Forgery (CSRF) vulnerability in Media Library Helper plugin <= 1.2.0 versions. Media Library Helper after 1.2.0 Fix from $1,9502023-07-18 HIGH 8.8 CVE-2023-37387 Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions. Classified Listing after 2.4.5 Fix from $1,9502023-07-18 HIGH 8.8 CVE-2023-37889 Cross-Site Request Forgery (CSRF) vulnerability in WPAdmin WPAdmin AWS CDN plugin <= 2.0.13 versions. Aws Cdn after 2.0.13 Fix from $1,9502023-07-18