Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2022-23679 AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attacker to execute commands in th… Aos Cx 10.06.0210 / 10.08.1070+ Fix from $1,9502022-09-06 HIGH 8.8 CVE-2022-23680 AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attacker to execute commands in th… Aos Cx 10.06.0210 / 10.08.1070+ Fix from $1,9502022-09-06 HIGH 8.8 CVE-2022-3121 A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problematic. Affected by this vulner… Online Employee Leave Management System Mitigation only Fix from $1,9502022-09-05 HIGH 7.5 CVE-2022-36076 NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional … Nodebb 1.17.2+ Fix from $1,9502022-09-02 MEDIUM 6.5 CVE-2020-4301 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un… Cognos Analytics 11.1.7 / 11.2.3+ Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2021-20468 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un… Cognos Analytics 11.1.7 / 11.2.3+ Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2021-29823 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un… Cognos Analytics 11.1.7 / 11.2.3+ Fix from $1,6002022-09-01 HIGH 8.8 CVE-2022-36373 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress. Mp3 Jplayer after 2.7.3 Fix from $1,9502022-09-01 MEDIUM 6.1 CVE-2022-36796 Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in CallRail, Inc. CallRail Phone Call Tracking plugin <=… Callrail Phone Call Tracking after 0.4.9 Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2022-3017 Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38. Froxlor 0.10.38+ Fix from $1,6002022-08-28 HIGH 8.8 CVE-2022-36546 Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php. Edoc Doctor Appointment System No fix yet Fix from $1,9502022-08-26 HIGH 8.8 CVE-2022-31773 IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and … Datapower Gateway 10.5.0+ Fix from $1,9502022-08-26 MEDIUM 6.5 CVE-2021-39394 mm-wiki v0.2.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add user accounts and modify user … Mm Wiki No fix yet Fix from $1,6002022-08-26 HIGH 8.8 CVE-2022-36288 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. Download Manager after 3.2.48 Fix from $1,9502022-08-23 HIGH 8.8 CVE-2022-36292 Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress. Gallery Photoblocks after 1.2.6 Fix from $1,9502022-08-23 HIGH 8.8 CVE-2022-36379 Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress. Yukassa For Woocommerce after 2.3.0 Fix from $1,9502022-08-23 HIGH 8.8 CVE-2022-36389 Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress. Better Messages after 1.9.9.148 Fix from $1,9502022-08-23 HIGH 8.8 CVE-2022-29468 A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lea… Avideo No fix yet Fix from $1,9502022-08-22 HIGH 8.8 CVE-2022-34347 Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. Download Manager after 3.2.48 Fix from $1,9502022-08-22 HIGH 8.8 CVE-2022-36346 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress. Maxbuttons after 9.2 Fix from $1,9502022-08-22 MEDIUM 6.5 CVE-2022-2555 The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a l… Yotpo Reviews For Woocommerce after 2.0.4 Fix from $1,6002022-08-22 MEDIUM 5.4 CVE-2022-2312 The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in us… Student Result Or Employee Database 1.7.5+ Fix from $1,6002022-08-22 MEDIUM 5.4 CVE-2022-2375 The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated use… Wp Sticky Button 1.4.1+ Fix from $1,6002022-08-22 MEDIUM 6.5 CVE-2022-2388 The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to… Wp Coder 2.5.3+ Fix from $1,6002022-08-22 HIGH 8.0 CVE-2021-36852 Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress. Wp Hotel Booking after 1.10.5 Fix from $1,9502022-08-22 MEDIUM 5.4 CVE-2021-24912 The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attac… Transposh Wordpress Translation 1.0.8+ Fix from $1,6002022-08-22 HIGH 8.8 CVE-2022-36577 An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin. Jizhicms No fix yet Fix from $1,9502022-08-19 HIGH 8.8 CVE-2022-36579 Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF). Wellcms No fix yet Fix from $1,9502022-08-19 HIGH 8.8 CVE-2022-36224 XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF). Xunruicms No fix yet Fix from $1,9502022-08-19 HIGH 8.8 CVE-2022-36225 EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add. Eyoucms No fix yet Fix from $1,9502022-08-19