Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2016-15005 CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values an… Golf 0.3.0+ Fix from $1,9502022-12-27 MEDIUM 6.5 CVE-2022-4766 A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of … Dolibarr Project Timesheet 4.5.6+ Fix from $1,6002022-12-27 MEDIUM 6.5 CVE-2020-36633 A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file bloc… Moodle Block Sitenews 1.1+ Fix from $1,6002022-12-27 HIGH 8.8 CVE-2020-28191 The console in Togglz before 2.9.4 allows CSRF. Togglz 2.9.4+ Fix from $1,9502022-12-26 MEDIUM 6.5 CVE-2022-46491 A Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allows attackers to arbitrarily a… Nbnbk No fix yet Fix from $1,6002022-12-22 HIGH 8.8 CVE-2020-36625 A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocket.Upgrader of the file main.g… Chat Patch available Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-4646 Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4. Rdiffweb 2.5.4+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2021-4275 A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation lea… Pyambic Pentameter Patch available Fix from $1,9502022-12-21 HIGH 8.8 CVE-2022-4633 A vulnerability was found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this issue is some unknown functionality of th… Auto Upload Images 3.3.1+ Fix from $1,9502022-12-21 HIGH 8.8 CVE-2021-4268 A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads t… Phpredisadmin 1.18.0+ Fix from $1,9502022-12-21 MEDIUM 6.5 CVE-2020-36622 A vulnerability was found in sah-comp bienlein and classified as problematic. This issue affects some unknown processing. The manipulation leads to c… Bienlein 2020-09-28+ Fix from $1,6002022-12-21 MEDIUM 6.5 CVE-2020-36623 A vulnerability was found in Pengu. It has been declared as problematic. Affected by this vulnerability is the function runApp of the file src/index.… Pengu 2020-11-02+ Fix from $1,6002022-12-21 MEDIUM 6.5 CVE-2022-4024 The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing … Pie Register 3.8.1.3+ Fix from $1,6002022-12-19 HIGH 8.8 CVE-2022-4604 A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerability is the function registe… Wp English Wp Admin 1.5.2+ Fix from $1,9502022-12-18 HIGH 8.8 CVE-2022-4564 A vulnerability classified as problematic has been found in University of Central Florida Materia up to 9.0.0. This affects the function before of th… Materia after 9.0.0 Fix from $1,9502022-12-16 MEDIUM 6.5 CVE-2022-3427 The Corner Ad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.56. This is due to missing or in… Corner Ad after 1.0.56 Fix from $1,6002022-12-15 HIGH 8.8 CVE-2022-46074 Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF pr… Helmet Store Showroom No fix yet Fix from $1,9502022-12-14 MEDIUM 6.5 CVE-2022-46059 AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF). Aerocms No fix yet Fix from $1,6002022-12-13 MEDIUM 6.5 CVE-2022-3946 The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, u… Welcart E Commerce 2.8.4+ Fix from $1,6002022-12-12 HIGH 8.1 CVE-2022-3999 The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated us… Woocommerce Shipping after 1.2.11 Fix from $1,9502022-12-12 MEDIUM 6.5 CVE-2022-3879 The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX ac… Car Dealer 3.05+ Fix from $1,6002022-12-12 MEDIUM 6.5 CVE-2022-3880 The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper auth… Antihacker 4.20+ Fix from $1,6002022-12-12 MEDIUM 5.7 CVE-2022-3881 The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.4… Wptools 3.43+ Fix from $1,6002022-12-12 MEDIUM 6.5 CVE-2022-3882 The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and… Wp Memory 2.46+ Fix from $1,6002022-12-12 MEDIUM 6.5 CVE-2022-3883 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not have proper authorisation an… Stopbadbots 7.24+ Fix from $1,6002022-12-12 MEDIUM 5.4 CVE-2022-3853 Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a web browser of the victim by i… Supra Csv Parser after 4.0.3 Fix from $1,6002022-12-12 HIGH 8.8 CVE-2022-45980EPSS 7% Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet . Ax12 Firmware No fix yet Fix from $1,9502022-12-12 MEDIUM 6.5 CVE-2022-46688 A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins conne… Sonar Gerrit after 377.v8f3808963dc5 Fix from $1,6002022-12-12 HIGH 8.8 CVE-2022-41296 IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr… Db2 Mitigation only Fix from $1,9502022-12-12 MEDIUM 6.5 CVE-2022-4397 A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file applicati… Zend Blog 2 Patch available Fix from $1,6002022-12-10