Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2023-35917 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions. Paypal Payments after 2.0.4 Fix from $1,9502023-06-22 HIGH 8.8 CVE-2023-23795 Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Form Builder plugin <= 1.9.9.0 versions. Form Builder after 1.9.9.0 Fix from $1,9502023-06-22 HIGH 8.8 CVE-2022-3372 There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator passwords through a Cross Site Request Fo… Netman 204 Firmware Mitigation only Fix from $1,9502023-06-21 HIGH 8.8 CVE-2020-21252 Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the up… Hongcms No fix yet Fix from $1,9502023-06-20 HIGH 8.0 CVE-2020-21366 Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php. Greencms No fix yet Fix from $1,9502023-06-20 HIGH 8.8 CVE-2023-2533 KEVEPSS 29% A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable a… Papercut Mf 20.1.8 / 21.2.12+ Fix from $1,9502023-06-20 MEDIUM 6.5 CVE-2020-20502 Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function. Yzmcms No fix yet Fix from $1,6002023-06-20 HIGH 8.8 CVE-2020-20726 Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user para… Gila Cms No fix yet Fix from $1,9502023-06-20 HIGH 8.8 CVE-2023-34373 Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions. Zephyr Project Manager after 3.3.93 Fix from $1,9502023-06-19 HIGH 7.8 CVE-2023-30759 The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected… Printer Driver Packager Nx 1.1.26+ Fix from $1,9502023-06-19 HIGH 8.8 CVE-2023-25055 Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions. Google Xml Sitemap For Videos after 2.6.1 Fix from $1,9502023-06-15 HIGH 8.8 CVE-2023-27634 Cross-Site Request Forgery (CSRF) vulnerability allows arbitrary file upload in Shingo Intrepidity plugin <= 1.5.1 versions. Intrepidity after 1.5.1 Fix from $1,9502023-06-15 HIGH 8.8 CVE-2023-23802 Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions. Ht Easy Ga4 \(google Analytics 4\) 1.0.7+ Fix from $1,9502023-06-15 HIGH 8.8 CVE-2023-25450 Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin <= 2.25.1 versions. Givewp 2.25.2+ Fix from $1,9502023-06-15 HIGH 8.8 CVE-2023-25449 Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions. Cformsii 15.0.5+ Fix from $1,9502023-06-15 HIGH 8.8 CVE-2023-35030 Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP… Dxp 7.4.3.77+ Fix from $1,9502023-06-15 MEDIUM 6.5 CVE-2023-35148 A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect t… Digital.ai App Management Publisher after 2.6 Fix from $1,6002023-06-14 HIGH 8.0 CVE-2023-35141 In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includ… Jenkins 2.400 / 2.401.1+ Fix from $1,9502023-06-14 MEDIUM 6.1 CVE-2022-42880 Cross-Site Request Forgery (CSRF) vulnerability in Ali Irani Auto Upload Images plugin <= 3.3 versions allows Stored Cross-Site Scripting (XSS). Auto Upload Images 3.3.1+ Fix from $1,6002023-06-13 HIGH 8.8 CVE-2023-30901 A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA00-2AA0) (All versions < V3.11)… Q200 Firmware 2.70+ Fix from $1,9502023-06-13 MEDIUM 6.5 CVE-2023-2599 The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby… Active Directory Integration \/ Ldap Integration after 4.1.4 Fix from $1,6002023-06-09 MEDIUM 5.4 CVE-2023-2526 The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.7. This is due to missin… Easy Google Maps after 1.11.7 Fix from $1,6002023-06-09 MEDIUM 5.4 CVE-2023-2067 The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce validation … Announcement \& Notification Banner Bulletin after 3.7.0 Fix from $1,6002023-06-09 HIGH 8.1 CVE-2023-0292 The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to m… Quiz And Survey Master after 8.0.8 Fix from $1,9502023-06-09 HIGH 8.0 CVE-2023-31200 PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a rep… Vuforia Studio 9.9+ Fix from $1,9502023-06-07 HIGH 8.8 CVE-2021-4349 The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This ma… Process Steps Template Designer after 1.2.1 Fix from $1,9502023-06-07 HIGH 8.8 CVE-2020-36717 The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect non… Kali Forms after 2.1.1 Fix from $1,9502023-06-07 HIGH 8.8 CVE-2020-36707 The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This… Nifty Coming Soon \& Maintenance Mode Page 1.58+ Fix from $1,9502023-06-07 HIGH 8.8 CVE-2015-10116 A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function … Favicon By Realfavicongenerator after 1.2.12 Fix from $1,9502023-06-06 MEDIUM 6.5 CVE-2023-33409 Minical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/company.php. Minical No fix yet Fix from $1,6002023-06-05