Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2023-0820 The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrar… User Role 1.6.7+ Fix from $1,9502023-04-03 HIGH 8.8 CVE-2023-28674 A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect to a p… Octoperf Load Testing after 4.5.2 Fix from $1,9502023-04-02 HIGH 8.8 CVE-2023-28676 A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers to create a Pipeline based o… Convert To Pipeline after 1.0 Fix from $1,9502023-04-02 HIGH 8.8 CVE-2022-42447 HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate… Hcl Compass 2.2.1+ Fix from $1,9502023-04-02 HIGH 8.8 CVE-2023-23861 Cross-Site Request Forgery (CSRF) vulnerability in German Mesky GMAce plugin <= 1.5.2 versions. Gmace after 1.5.2 Fix from $1,9502023-03-29 HIGH 8.8 CVE-2022-38077 Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversi… Popup Anything after 2.2.1 Fix from $1,9502023-03-29 HIGH 8.8 CVE-2023-1509 The GMAce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing nonce vali… Gmace after 1.5.2 Fix from $1,9502023-03-29 HIGH 8.0 CVE-2023-28718 Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. T… Osprey Pump Controller Firmware Mitigation only Fix from $1,9502023-03-28 MEDIUM 6.5 CVE-2023-0335 The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delet… Wp Shamsi after 4.3.3 Fix from $1,6002023-03-27 MEDIUM 6.5 CVE-2023-0336 The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low… Ooohboi Steroids For Elementor 2.1.5+ Fix from $1,6002023-03-27 HIGH 8.8 CVE-2022-30705 Cross-Site Request Forgery (CSRF) vulnerability in Pankaj Jha WordPress Ping Optimizer plugin <= 2.35.1.2.3 versions. Wordpress Ping Optimizer 2.35.1.3.0+ Fix from $1,9502023-03-27 HIGH 8.8 CVE-2023-28335 The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk. Moodle Patch available Fix from $1,9502023-03-23 HIGH 8.1 CVE-2023-20113 A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a c… Sd Wan 20.6.5+ Fix from $1,9502023-03-23 MEDIUM 6.7 CVE-2023-0870 A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can potentially allow an attacke… Horizon 31.0.6 / 2020.1.33+ Fix from $1,6002023-03-22 HIGH 8.8 CVE-2023-22678 Cross-Site Request Forgery (CSRF) vulnerability in Rafael Dery Superior FAQ plugin <= 1.0.2 versions. Superior Faq after 1.0.2 Fix from $1,9502023-03-20 HIGH 8.8 CVE-2023-23721 Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions. Admin Log after 1.50 Fix from $1,9502023-03-20 MEDIUM 6.5 CVE-2023-22681 Cross-Site Request Forgery (CSRF) vulnerability in Aarvanshinfotech Online Exam Software: eExamhall plugin <= 4.0 versions. Eexamhall Project after 4.0 Fix from $1,6002023-03-20 HIGH 8.8 CVE-2022-46854 Cross-Site Request Forgery (CSRF) vulnerability in Obox Themes Launchpad – Coming Soon & Maintenance Mode plugin <= 1.0.13 versions. Launchpad Coming Soon \& Maintenance Mode Plugin after 1.0.13 Fix from $1,9502023-03-17 HIGH 8.8 CVE-2022-46867 Cross-Site Request Forgery (CSRF) vulnerability in Chasil Universal Star Rating plugin <= 2.1.0 version. Universal Star Rating after 2.1.0 Fix from $1,9502023-03-17 MEDIUM 6.3 CVE-2023-1472 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This… Rapidload Power Up For Autoptimize 1.7.2+ Fix from $1,6002023-03-17 HIGH 8.8 CVE-2022-38063 Cross-Site Request Forgery (CSRF) vulnerability in Social Login WP plugin <= 5.0.0.0 versions. Social Login Wp after 5.0.0.0 Fix from $1,9502023-03-16 HIGH 8.8 CVE-2022-47427 Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions. My Calendar after 3.3.24.1 Fix from $1,9502023-03-15 HIGH 8.8 CVE-2023-25708 Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions. Wp Vr 8.2.8+ Fix from $1,9502023-03-15 HIGH 8.8 CVE-2023-25709 Cross-Site Request Forgery (CSRF) vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.11 versions. Locatoraid after 3.9.11 Fix from $1,9502023-03-15 HIGH 8.8 CVE-2023-25968 Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Madalin Ungureanu, Antohe Cristian Client Portal – Private user pages and login plugin… Client Portal 1.1.9+ Fix from $1,9502023-03-15 MEDIUM 6.5 CVE-2023-27234 A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration changes within the appli… Jizhicms No fix yet Fix from $1,6002023-03-15 MEDIUM 5.4 CVE-2023-24920 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Dynamics 365 9.0.45.11 / 9.1.16.20+ Fix from $1,6002023-03-14 MEDIUM 6.5 CVE-2023-27073 A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST re… Online Food Ordering System Mitigation only Fix from $1,6002023-03-14 HIGH 8.8 CVE-2022-47143 Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions. Multiple Page Generator after 3.3.9 Fix from $1,9502023-03-14 HIGH 8.8 CVE-2022-47147 Cross-Site Request Forgery (CSRF) vulnerability in Kesz1 Technologies ipBlockList plugin <= 1.0 versions. Ipblocklist after 1.0 Fix from $1,9502023-03-14