Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2022-27628 Cross-Site Request Forgery (CSRF) vulnerability in AA-Team WZone – Lite Version plugin 3.1 Lite versions. Wzone Mitigation only Fix from $1,6002023-02-06 MEDIUM 6.5 CVE-2023-0674 A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the fi… Xxl Job No fix yet Fix from $1,6002023-02-04 HIGH 8.8 CVE-2021-36569 Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2. Fuel Cms Patch available Fix from $1,9502023-02-03 HIGH 8.8 CVE-2021-36570 Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---. Fuel Cms Patch available Fix from $1,9502023-02-03 MEDIUM 6.5 CVE-2021-37234 Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensit… Modern Honey Network 2021-10-30+ Fix from $1,6002023-02-03 HIGH 8.8 CVE-2021-36443 Cross Site Request Forgery vulnerability in imcat 5.4 allows remote attackers to escalate privilege via lack of token verification. Imcat No fix yet Fix from $1,9502023-02-03 HIGH 8.8 CVE-2021-36444 Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token generation… Imcat No fix yet Fix from $1,9502023-02-03 HIGH 8.8 CVE-2022-47132 A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users. Academy Lms 5.10+ Fix from $1,9502023-02-03 HIGH 8.8 CVE-2022-46842 Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions. Js Help Desk 2.7.2+ Fix from $1,9502023-02-02 HIGH 8.8 CVE-2022-46815 Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 versions. Conditional Shipping For Woocommerce 2.3.2+ Fix from $1,9502023-02-02 HIGH 8.8 CVE-2022-45067 Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions. Exclusive Addons For Elementor 2.6.2+ Fix from $1,9502023-02-02 HIGH 8.8 CVE-2022-45807 Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions. Wp Mail Log 1.0.2+ Fix from $1,9502023-02-02 HIGH 8.8 CVE-2022-40692 Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions. Sunshine Photo Cart 2.9.14+ Fix from $1,9502023-02-02 HIGH 8.8 CVE-2022-44585 Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions. Homepage Pop Up after 1.2.5 Fix from $1,9502023-02-02 HIGH 8.8 CVE-2022-36401 Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet – For WooCommerce plugin <= 1.3.24 versions. Terawallet 1.4.0+ Fix from $1,9502023-02-02 MEDIUM 6.5 CVE-2023-0642 Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0. Squidex 7.4.0+ Fix from $1,6002023-02-02 MEDIUM 6.5 CVE-2023-25015 Clockwork Web before 0.1.2, when Rails before 5.2 is used, allows CSRF. Clockwork Web 0.1.2+ Fix from $1,6002023-02-02 MEDIUM 6.3 CVE-2023-23750 An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messag… Joomla\! after 4.2.6 Fix from $1,6002023-02-01 HIGH 8.8 CVE-2023-20856 VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of th… Vrealize Operations after 8.6.4 Fix from $1,9502023-02-01 MEDIUM 6.5 CVE-2022-32516 A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the … Conext Combox Firmware Mitigation only Fix from $1,6002023-01-30 MEDIUM 6.1 CVE-2022-4552 The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, w… Fl3r Feelbox after 8.1 Fix from $1,6002023-01-30 MEDIUM 5.4 CVE-2022-43980 There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a networ… Pandora Fms 766+ Fix from $1,6002023-01-27 HIGH 8.1 CVE-2023-0554 The Quick Restaurant Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to mi… Quick Restaurant Menu 2.1.0+ Fix from $1,9502023-01-27 MEDIUM 6.5 CVE-2023-24457 A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into lo… Keycloak Authentication after 2.3.0 Fix from $1,6002023-01-26 HIGH 8.8 CVE-2023-24458 A cross-site request forgery (CSRF) vulnerability in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified … Bearychat after 3.0.2 Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-24446 A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick users into logging in to the att… Openid after 2.4 Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-24447 A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attacker-spec… Rabbitmq Consumer after 2.8 Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-24452 A cross-site request forgery (CSRF) vulnerability in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers to connect to an attacker-sp… Testquality Updater after 1.3 Fix from $1,9502023-01-26 MEDIUM 5.7 CVE-2023-24428 A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in … Bitbucket Oauth 0.13+ Fix from $1,6002023-01-26 HIGH 8.8 CVE-2023-24432 A cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers to connect to an attacker-sp… Orka By Macstadium 1.32+ Fix from $1,9502023-01-26