Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2020-23593 A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to cond… Op Xt71000n Firmware Mitigation only Fix from $1,6002022-11-23 HIGH 8.8 CVE-2022-41919 Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight… Fastify 3.29.4 / 4.10.2+ Fix from $1,9502022-11-22 HIGH 8.8 CVE-2022-44737 Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress. All In One Wp Security \& Firewall after 5.1.0 Fix from $1,9502022-11-22 MEDIUM 6.5 CVE-2020-23582 A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a c… Op Xt71000n Firmware Mitigation only Fix from $1,6002022-11-21 HIGH 8.8 CVE-2022-44740 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress. Creative Mail after 1.5.4 Fix from $1,9502022-11-18 HIGH 8.8 CVE-2022-45073 Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress. Wordpress Rest Api Authentication after 2.4.0 Fix from $1,9502022-11-18 HIGH 8.8 CVE-2022-41685 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Viszt Péter's Integration for Szamlazz.hu & WooCommerce plugin <= 5.6.3.2 and Csomagpon… Integration For Szamlazz.hu \& Woocommerce 1.9.0.3 / 5.6.3.3+ Fix from $1,9502022-11-18 MEDIUM 6.1 CVE-2022-41615 Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress. Store Locator 1.4.6+ Fix from $1,6002022-11-18 HIGH 8.8 CVE-2022-41634 Cross-Site Request Forgery (CSRF) vulnerability in Media Library Folders plugin <= 7.1.1 on WordPress. Media Library Folders 7.1.2+ Fix from $1,9502022-11-18 HIGH 8.8 CVE-2022-40695 Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress. Seo Redirection 9.1+ Fix from $1,9502022-11-18 MEDIUM 6.1 CVE-2022-38075 Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Mantenimiento web plugin <= 0.13 on WordPress. Mantenimiento Web 0.14+ Fix from $1,6002022-11-18 HIGH 8.8 CVE-2022-40686 Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. Creative Mail 1.6.0+ Fix from $1,9502022-11-18 HIGH 8.8 CVE-2022-40687 Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. Creative Mail 1.6.0+ Fix from $1,9502022-11-18 HIGH 8.8 CVE-2022-40192 Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. Wpforo Forum after 2.0.9 Fix from $1,9502022-11-17 HIGH 8.8 CVE-2022-45071 Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress. Wpml 4.5.14+ Fix from $1,9502022-11-17 HIGH 8.8 CVE-2022-42246 Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account. Duofox Cms No fix yet Fix from $1,9502022-11-17 HIGH 8.8 CVE-2022-4013 A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the … Hospital Management Center No fix yet Fix from $1,9502022-11-16 HIGH 8.8 CVE-2022-3240 The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missi… Follow Me Plugin after 3.1.1 Fix from $1,9502022-11-15 HIGH 8.8 CVE-2022-35613 Konker v2.3.9 was to discovered to contain a Cross-Site Request Forgery (CSRF). Konker Platform Mitigation only Fix from $1,9502022-11-15 HIGH 8.8 CVE-2022-44387 EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member modul… Eyoucms Mitigation only Fix from $1,9502022-11-14 MEDIUM 6.5 CVE-2022-44389 EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows at… Eyoucms Mitigation only Fix from $1,6002022-11-14 HIGH 8.8 CVE-2022-43323 EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module. Eyoucms No fix yet Fix from $1,9502022-11-14 HIGH 8.8 CVE-2022-43693 Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use th… Concrete Cms 8.5.10+ Fix from $1,9502022-11-14 MEDIUM 6.5 CVE-2022-3632 The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logge… Oauth Client after 1.1.0 Fix from $1,6002022-11-14 MEDIUM 6.5 CVE-2022-3538 The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenti… Webmaster Tools Verification after 1.2 Fix from $1,6002022-11-14 MEDIUM 6.5 CVE-2022-2449 The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actio… Resmush.it Image Optimizer 0.4.7+ Fix from $1,6002022-11-14 MEDIUM 6.5 CVE-2022-45130 Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of… Obsidian No fix yet Fix from $1,6002022-11-10 HIGH 8.8 CVE-2022-43031 DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and mod… Dedecms No fix yet Fix from $1,9502022-11-09 HIGH 8.8 CVE-2022-44741 Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPre… Testimonial Slider after 1.3.1 Fix from $1,9502022-11-08 MEDIUM 5.4 CVE-2022-40632 Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion. Wpforo Forum after 2.0.5 Fix from $1,6002022-11-08