Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2022-23765 This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote … Nas1dual Firmware 1.4.86+ Fix from $1,9502022-08-17 HIGH 8.8 CVE-2022-36312 Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelo… Airvelocity 1500 Firmware Mitigation only Fix from $1,9502022-08-16 HIGH 8.8 CVE-2022-38359 Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An atta… Eyes Of Network Web No fix yet Fix from $1,9502022-08-15 HIGH 8.8 CVE-2022-2381 The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attac… E Unlocked Student Result after 1.0.4 Fix from $1,9502022-08-15 HIGH 8.8 CVE-2022-35943 Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubd… Codeigniter 4.2.3+ Fix from $1,9502022-08-12 MEDIUM 5.7 CVE-2022-37043 An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked … Collaboration Patch available Fix from $1,6002022-08-12 MEDIUM 6.5 CVE-2022-2355 The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change … Easy Username Updater 1.0.5+ Fix from $1,6002022-08-08 HIGH 8.8 CVE-2022-33201 Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the… Mailerlite Signup Forms 1.5.8+ Fix from $1,9502022-08-05 MEDIUM 5.4 CVE-2016-3098 Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization cod… Administrate 0.1.5+ Fix from $1,6002022-08-05 MEDIUM 6.5 CVE-2022-28731EPSS 57% A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacke… Jspwiki 2.11.3+ Fix from $1,6002022-08-04 HIGH 8.8 CVE-2022-34158 A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group pri… Jspwiki 2.11.3+ Fix from $1,9502022-08-04 HIGH 8.8 CVE-2022-34937 Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers t… U5cms No fix yet Fix from $1,9502022-08-03 HIGH 8.8 CVE-2022-34161 IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted … Cics Tx Patch available Fix from $1,9502022-08-01 MEDIUM 5.4 CVE-2022-2171 The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logg… Progressive License after 1.1.0 Fix from $1,6002022-08-01 HIGH 8.8 CVE-2022-2184 The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abu… Captcha 4wp 7.1.0+ Fix from $1,9502022-08-01 HIGH 8.8 CVE-2022-2245 The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a … Counter Box 1.2.1+ Fix from $1,9502022-08-01 MEDIUM 6.5 CVE-2022-2260 The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dat… Givewp 2.21.3+ Fix from $1,6002022-08-01 HIGH 8.8 CVE-2022-26309 Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator grou… Pandora Fms after 7.0_ng_759 Fix from $1,9502022-08-01 HIGH 8.8 CVE-2022-36920 A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified … Coverity after 1.11.4 Fix from $1,9502022-07-27 HIGH 8.0 CVE-2022-36916 A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup. Google Cloud Backup after 0.6 Fix from $1,9502022-07-27 MEDIUM 6.5 CVE-2022-36906 A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to connect to an attacker-s… Openshift Deployer after 1.2.0 Fix from $1,6002022-07-27 MEDIUM 6.5 CVE-2022-36908 A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence … Openshift Deployer after 1.2.0 Fix from $1,6002022-07-27 MEDIUM 6.5 CVE-2022-36911 A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers to connect to an attacker-specifi… Openstack Heat after 1.5 Fix from $1,6002022-07-27 HIGH 8.8 CVE-2022-36882 A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to u… Git after 4.11.3 Fix from $1,9502022-07-27 HIGH 8.8 CVE-2022-35286 IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut… Security Verify Information Queue Patch available Fix from $1,9502022-07-26 HIGH 8.0 CVE-2022-22686 Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijac… Calendar 2.3.4-0631+ Fix from $1,9502022-07-26 HIGH 8.8 CVE-2022-35285 IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut… Security Verify Information Queue Patch available Fix from $1,9502022-07-25 HIGH 8.8 CVE-2021-40335 A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was… Modular Switchgear Monitoring Firmware after 2.2.0 Fix from $1,9502022-07-25 MEDIUM 6.1 CVE-2022-2071 The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping… Name Directory 1.25.4+ Fix from $1,6002022-07-25 HIGH 8.8 CVE-2022-34367 Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unau… Emc Data Protection Central 19.7+ Fix from $1,9502022-07-21