Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2023-27430 Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Mass Delete Unused Tags plugin <= 2.0.0 versions. Mass Delete Unused Tags 3.0.0+ Fix from $1,9502023-05-18 HIGH 8.8 CVE-2023-2528 The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.24. This is due … Contact Form after 1.7.24 Fix from $1,9502023-05-17 HIGH 8.8 CVE-2023-32998 A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to connect to an attacker-specified… Appspider after 1.0.15 Fix from $1,9502023-05-16 MEDIUM 5.4 CVE-2023-33006 A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the… Wso2 Oauth after 1.0 Fix from $1,6002023-05-16 HIGH 8.8 CVE-2023-32991 A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP reque… Saml Single Sign On after 2.0.2 Fix from $1,9502023-05-16 HIGH 8.8 CVE-2023-32995 A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST … Saml Single Sign On after 2.0.0 Fix from $1,9502023-05-16 HIGH 8.8 CVE-2023-32987 A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-s… Reverse Proxy Auth after 1.7.4 Fix from $1,9502023-05-16 HIGH 8.8 CVE-2023-32989 A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an … Azure Vm Agents after 852.v8d35f0960a_43 Fix from $1,9502023-05-16 MEDIUM 6.5 CVE-2023-28361 A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential info… Unifi Os 3.0.13+ Fix from $1,6002023-05-11 HIGH 8.8 CVE-2023-2444 A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways.… Factorytalk Vantagepoint 8.40+ Fix from $1,9502023-05-11 HIGH 8.8 CVE-2022-45846 Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro for WordPress - Interactive SVG Image Map Builder plugin < 5.6.9 versions. Interactive Svg Image Map Builder 5.6.9+ Fix from $1,9502023-05-10 HIGH 8.8 CVE-2023-27889 Cross-site request forgery (CSRF) vulnerability in LIQUID SPEECH BALLOON versions prior to 1.2 allows a remote unauthenticated attacker to hijack the… Liquid Speech Balloon 1.2+ Fix from $1,9502023-05-10 HIGH 8.8 CVE-2023-25832 There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authoriz… Portal For Arcgis after 11.0 Fix from $1,9502023-05-09 HIGH 8.8 CVE-2020-23363 Cross Site Request Forgery (CSRF) vulnerability found in Verytops Verydows all versions that allows an attacker to execute arbitrary code via a craft… Verydows No fix yet Fix from $1,9502023-05-09 MEDIUM 6.5 CVE-2023-0522 The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could … Enable\/disable Auto Login When Register after 1.1.0 Fix from $1,6002023-05-08 HIGH 8.8 CVE-2020-18131 Cross Site Request Forgery (CSRF) vulnerability in Bluethrust Clan Scripts v4 allows attackers to escilate privledges to an arbitrary account via a c… Clanscripts No fix yet Fix from $1,9502023-05-08 MEDIUM 6.5 CVE-2020-22334 Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via crafted request to /admin/admi… Beescms No fix yet Fix from $1,6002023-05-08 HIGH 8.8 CVE-2020-36065 Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts via system/admin/admin_save. Flycms No fix yet Fix from $1,9502023-05-08 HIGH 8.8 CVE-2023-2552 Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1. Bumsys 2.1.1+ Fix from $1,9502023-05-05 MEDIUM 6.5 CVE-2023-1965 An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, a… GitLab 15.9.6 / 15.10.5+ Fix from $1,6002023-05-03 HIGH 8.8 CVE-2023-25967 Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo plugin <= 6.0.2.0 versions. Peepso 6.0.3.0+ Fix from $1,9502023-05-03 HIGH 8.8 CVE-2023-23790 Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions. Pods 2.9.11+ Fix from $1,9502023-05-03 HIGH 8.8 CVE-2023-22691 Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions. Category Specific Rss Feed Subscription 2.2+ Fix from $1,9502023-05-03 HIGH 8.8 CVE-2023-29815 mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). Mccms No fix yet Fix from $1,9502023-04-28 MEDIUM 6.5 CVE-2023-2307 Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0. Qwik 0.104.0+ Fix from $1,6002023-04-26 HIGH 8.8 CVE-2022-40724 The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET request… Pingfederate after 11.2.2 Fix from $1,9502023-04-25 MEDIUM 6.5 CVE-2023-26841 A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is curr… Churchcrm No fix yet Fix from $1,6002023-04-25 MEDIUM 5.3 CVE-2023-26840 A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administr… Churchcrm No fix yet Fix from $1,6002023-04-25 HIGH 8.8 CVE-2023-31061 Repetier Server through 1.4.10 does not have CSRF protection. Repetier Server after 1.4.10 Fix from $1,9502023-04-24 HIGH 8.8 CVE-2022-45074 Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <= 1.0.22 ve… Activity Reactions For Buddypress after 1.0.22 Fix from $1,9502023-04-23