Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2022-41136 Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12… Shortcodes Ultimate after 5.12.0 Fix from $1,9502022-11-08 HIGH 8.8 CVE-2022-38137 Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress. Analytify Google Analytics Dashboard 4.2.3+ Fix from $1,9502022-11-08 MEDIUM 6.5 CVE-2022-40128 Cross-Site Request Forgery (CSRF) vulnerability in Advanced Order Export For WooCommerce plugin <= 3.3.2 on WordPress leading to export file download. Advanced Order Export For Woocommerce 3.3.3+ Fix from $1,6002022-11-08 MEDIUM 6.5 CVE-2022-30694 The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to t… Simatic S7 1500 Software Controller 3.2.19+ Fix from $1,6002022-11-08 HIGH 8.8 CVE-2022-3536 The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate… Role Based Pricing For Woocommerce 1.6.3+ Fix from $1,9502022-11-07 HIGH 8.8 CVE-2022-3537 The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files … Role Based Pricing For Woocommerce 1.6.2+ Fix from $1,9502022-11-07 MEDIUM 5.3 CVE-2022-3489 The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allow… Wp Hide after 0.0.2 Fix from $1,6002022-11-07 HIGH 8.8 CVE-2022-38660 HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnera… Domino 9.0.1+ Fix from $1,9502022-11-04 HIGH 8.8 CVE-2022-20961 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond… Identity Services Engine 2.6.0+ Fix from $1,9502022-11-04 MEDIUM 5.4 CVE-2022-44627 Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 1.8.12 on WordPress allows attackers to create or delete sitemaps. Simple Seo after 1.8.12 Fix from $1,6002022-11-03 MEDIUM 5.4 CVE-2022-36404 Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions. Simple Seo after 1.8.12 Fix from $1,6002022-11-03 HIGH 8.8 CVE-2022-25952 Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress. Content Egg after 5.4.0 Fix from $1,9502022-11-03 HIGH 8.8 CVE-2022-30608 "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz… Infosphere Information Server Patch available Fix from $1,9502022-11-03 HIGH 8.8 CVE-2022-42751 CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from C… Candidats No fix yet Fix from $1,9502022-11-03 MEDIUM 6.5 CVE-2022-3852 The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or i… Vr Calendar 2.3.4+ Fix from $1,6002022-11-03 HIGH 8.8 CVE-2022-3776 The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… Restaurant Menu Food Ordering System Table Reservation 2.3.2+ Fix from $1,9502022-11-03 HIGH 8.8 CVE-2022-40291 The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to … Php Point Of Sale Mitigation only Fix from $1,9502022-10-31 MEDIUM 6.5 CVE-2022-3419 The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users … Automatic User Roles Switcher 1.1.2+ Fix from $1,6002022-10-31 MEDIUM 6.5 CVE-2022-40488 ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF). Processwire Patch available Fix from $1,6002022-10-31 HIGH 8.8 CVE-2022-43340 A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights t… Dzzoffice Mitigation only Fix from $1,9502022-10-27 HIGH 8.8 CVE-2022-41996 Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin install… Avada after 7.8.1 Fix from $1,9502022-10-27 MEDIUM 6.5 CVE-2022-2762 The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update the… Adminpad 2.2+ Fix from $1,6002022-10-25 HIGH 8.8 CVE-2022-42199 Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List. Simple Exam Reviewer Management System No fix yet Fix from $1,9502022-10-20 HIGH 8.8 CVE-2022-43407 Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, wh… Pipeline\ after 451.vf1a_a_4f405289 Fix from $1,9502022-10-19 MEDIUM 6.5 CVE-2022-43408 Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or a… Pipeline\ 2.27+ Fix from $1,6002022-10-19 HIGH 8.8 CVE-2022-41500 EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and… Eyoucms No fix yet Fix from $1,9502022-10-18 HIGH 8.8 CVE-2020-8976 The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with t… Zgr Tps200 Ng Firmware Mitigation only Fix from $1,9502022-10-17 HIGH 8.8 CVE-2022-23771 This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lac… Nas1dual Firmware 1.4.86+ Fix from $1,9502022-10-17 MEDIUM 6.5 CVE-2022-3082 The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logge… Discord Integration 2.1.6+ Fix from $1,6002022-10-17 MEDIUM 6.1 CVE-2022-3149 The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers … Wp Custom Cursors 3.0.1+ Fix from $1,6002022-10-17