Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2022-42070 Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF). Online Birth Certificate Management System No fix yet Fix from $1,9502022-10-14 MEDIUM 6.5 CVE-2022-41474 RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily change the password of any account. Rpcms No fix yet Fix from $1,6002022-10-13 HIGH 8.8 CVE-2022-41475 RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator account. Rpcms No fix yet Fix from $1,9502022-10-13 HIGH 8.1 CVE-2022-41489 WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server fro… Lq 09 Firmware No fix yet Fix from $1,9502022-10-13 HIGH 8.8 CVE-2022-34020 Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add ne… Iot Platform And Lorawan Network Server after 4.1.1000114 Fix from $1,9502022-10-13 MEDIUM 6.5 CVE-2022-42077 Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot. Ac1206 Firmware No fix yet Fix from $1,6002022-10-12 MEDIUM 6.5 CVE-2022-42078 Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet. Ac1206 Firmware No fix yet Fix from $1,6002022-10-12 MEDIUM 6.5 CVE-2022-42086 Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode. Ax1803 Firmware No fix yet Fix from $1,6002022-10-12 MEDIUM 6.5 CVE-2022-42087 Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot. Ax1803 Firmware No fix yet Fix from $1,6002022-10-12 MEDIUM 5.4 CVE-2022-32175 In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality… Adguardhome 0.108+ Fix from $1,6002022-10-11 HIGH 8.1 CVE-2022-40179 A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM… Desigo Pxm30 1 Firmware 02.20.126.11-37 / 02.20.126.11-41+ Fix from $1,9502022-10-11 MEDIUM 5.3 CVE-2022-40180 A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM… Desigo Pxm30 1 Firmware 02.20.126.11-37 / 02.20.126.11-41+ Fix from $1,6002022-10-11 HIGH 7.1 CVE-2022-3154 The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamla… Woo Billingo Plus 1.0.4 / 1.2.7+ Fix from $1,9502022-10-10 MEDIUM 6.5 CVE-2022-3208 The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new… Simple File List 4.4.12+ Fix from $1,6002022-10-10 MEDIUM 5.3 CVE-2022-2350 The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticate… Disable User Login after 1.0.1 Fix from $1,6002022-10-10 HIGH 8.8 CVE-2022-22493 IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute settin… Websphere Automation For Ibm Cloud Pak For Watson Aiops 1.4.3+ Fix from $1,9502022-10-07 HIGH 8.8 CVE-2022-2986 Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk. Moodle 3.11.9 / 4.0.3+ Fix from $1,9502022-10-06 MEDIUM 5.3 CVE-2022-2783 In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token Octopus Server 2022.1.3154 / 2022.2.7897+ Fix from $1,6002022-10-06 MEDIUM 5.4 CVE-2022-2839 The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthent… Zephyr Project Manager 3.2.55+ Fix from $1,6002022-10-03 HIGH 8.1 CVE-2022-39268 ### Impact In a CSRF attack, an innocent end user is tricked by an attacker into submitting a web request that they did not intend. This may cause ac… Orchest after 2022.09.9 Fix from $1,9502022-09-30 HIGH 8.8 CVE-2021-36854 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress. Booking Ultra Pro Appointments Booking Calendar after 1.1.4 Fix from $1,9502022-09-30 MEDIUM 6.1 CVE-2021-36855 Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress. Booking Ultra Pro Appointments Booking Calendar after 1.1.4 Fix from $1,6002022-09-30 HIGH 8.8 CVE-2020-35675 BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups. The appl… Online Invoicing System 3.0+ Fix from $1,9502022-09-29 MEDIUM 6.5 CVE-2022-3057 Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a craf… Chrome 105.0.5195.52+ Fix from $1,6002022-09-26 HIGH 7.5 CVE-2022-3119 The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unau… Oauth Client Single Sign On 3.0.4+ Fix from $1,9502022-09-26 HIGH 7.5 CVE-2022-2987 The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's set… Ldap Wp Login \/ Active Directory Integration 3.0.2+ Fix from $1,9502022-09-26 MEDIUM 5.4 CVE-2022-3024 The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated user… Simple Bitcoin Faucets after 1.7.0 Fix from $1,6002022-09-26 MEDIUM 5.4 CVE-2022-3025 The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged… Bitcoin\/altcoin Faucet after 1.6.0 Fix from $1,6002022-09-26 HIGH 8.8 CVE-2021-24890 The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthent… Scripts Organizer 3.0+ Fix from $1,9502022-09-26 HIGH 8.8 CVE-2022-38079 Cross-Site Request Forgery (CSRF) vulnerability Backup Scheduler plugin <= 1.5.13 at WordPress. Backup Scheduler after 1.5.13 Fix from $1,9502022-09-23