Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2022-20861 Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta… Nexus Dashboard 2.2+ Fix from $1,9502022-07-21 MEDIUM 6.5 CVE-2022-22359 IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to … Partner Engagement Manager 6.1.2.5 / 6.2.0.3+ Fix from $1,6002022-07-19 MEDIUM 6.5 CVE-2021-38868 IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker t… Engineering Requirements Quality Assistant On Premises Mitigation only Fix from $1,6002022-07-18 HIGH 8.8 CVE-2022-2435 The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1. This is due to missing nonc… Anymind Widget after 1.1 Fix from $1,9502022-07-18 HIGH 8.8 CVE-2022-2443 The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing… Freemind Wp Browser after 1.2 Fix from $1,9502022-07-18 HIGH 8.8 CVE-2022-1912 The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to … Button Widget Smartsoft Patch available Fix from $1,9502022-07-18 HIGH 8.8 CVE-2022-2001 The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing … Dx Share Selection 1.5+ Fix from $1,9502022-07-18 HIGH 8.8 CVE-2022-2039 The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.11. This is due to m… Free Live Chat Support after 1.0.11 Fix from $1,9502022-07-18 HIGH 8.8 CVE-2022-32320 A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file s… Ferdium after 5.8.1 Fix from $1,9502022-07-17 HIGH 8.8 CVE-2022-1672 The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, … Insights From Google Pagespeed 4.0.7+ Fix from $1,9502022-07-17 MEDIUM 6.1 CVE-2022-2146 The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking C… Import Csv Files after 1.0 Fix from $1,6002022-07-17 HIGH 8.8 CVE-2022-35228 SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This c… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502022-07-12 MEDIUM 6.5 CVE-2022-2091 The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via… Cache Images 3.2.1+ Fix from $1,6002022-07-11 MEDIUM 6.5 CVE-2022-1576 The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attack… Wp Maintenance Mode \& Coming Soon 2.4.5+ Fix from $1,6002022-07-11 MEDIUM 6.5 CVE-2022-1599 The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged… Admin Management Xtended 2.4.5+ Fix from $1,6002022-07-11 MEDIUM 5.4 CVE-2022-1626 The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logge… Sharebar after 1.4.1 Fix from $1,6002022-07-11 MEDIUM 6.5 CVE-2022-1732 The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login URL, which could allow attack… Rename Wp Login after 2.6.0 Fix from $1,6002022-07-11 MEDIUM 5.4 CVE-2022-1757 The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged i… Pagebar 2.70+ Fix from $1,6002022-07-11 MEDIUM 6.1 CVE-2022-2353 Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, … Microweber 1.2.20+ Fix from $1,6002022-07-09 MEDIUM 6.5 CVE-2015-1785 In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web applica… Nextgen Gallery 2.0.77.3+ Fix from $1,6002022-07-07 MEDIUM 6.5 CVE-2021-31677 An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwords. Pescms Team No fix yet Fix from $1,6002022-07-06 MEDIUM 6.5 CVE-2021-31678 An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user's company. Pescms Team No fix yet Fix from $1,6002022-07-06 MEDIUM 6.5 CVE-2021-31679 An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other members' account numbers. Pescms Team No fix yet Fix from $1,6002022-07-06 HIGH 8.8 CVE-2021-23163 JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects… Artifactory 6.23.38 / 7.33.6+ Fix from $1,9502022-07-06 MEDIUM 6.5 CVE-2022-1967 The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwant… Wp Championship 9.3+ Fix from $1,6002022-07-04 HIGH 8.0 CVE-2022-34792 A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-sp… Recipe after 1.2 Fix from $1,9502022-06-30 MEDIUM 6.5 CVE-2022-34789 A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix bui… Matrix Reloaded after 1.1.3 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34780 A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacke… Xebialabs Xl Release after 22.0.0 Fix from $1,6002022-06-30 HIGH 8.8 CVE-2017-20120 A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop… Trueconf Server No fix yet Fix from $1,9502022-06-29 MEDIUM 6.5 CVE-2022-31886 Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form. Marval Msm No fix yet Fix from $1,6002022-06-28