Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2022-34134 Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php. Jorani Patch available Fix from $1,9502022-06-28 HIGH 8.1 CVE-2022-1572 The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such a… Html2wp after 1.0.0 Fix from $1,9502022-06-27 CRITICAL 9.8 CVE-2022-1574EPSS 12% The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result,… Html2wp after 1.0.0 Fix from $2,3002022-06-27 MEDIUM 6.5 CVE-2022-1843 The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin chang… Mailpress after 7.2.1 Fix from $1,6002022-06-27 HIGH 8.1 CVE-2022-33121 A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link. Minicms No fix yet Fix from $1,9502022-06-24 HIGH 8.8 CVE-2022-34200 A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an atta… Convertigo Mobile Platform after 1.1 Fix from $1,9502022-06-23 HIGH 8.8 CVE-2022-34203 A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP … Easyqa after 1.0 Fix from $1,9502022-06-23 MEDIUM 6.5 CVE-2022-34205 A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests… Jianliao Notification after 1.1 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34207 A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specif… Beaker Builder after 1.10 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34209 A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to connect to an attacker-specified … Threadfix after 1.5.4 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34211 A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST reque… Vrealize Orchestrator after 3.0 Fix from $1,6002022-06-23 HIGH 8.8 CVE-2017-20090 A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability affects unknown code. The ma… Global Content Blocks No fix yet Fix from $1,9502022-06-23 MEDIUM 6.5 CVE-2017-20091 A vulnerability was found in File Manager Plugin 3.0.1. It has been classified as problematic. This affects an unknown part. The manipulation leads t… Library File Manager No fix yet Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-1828 The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to… Pdf24 Articles To Pdf after 4.2.2 Fix from $1,6002022-06-20 MEDIUM 6.5 CVE-2022-1829 The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to mak… Inline Google Maps after 5.11 Fix from $1,6002022-06-20 MEDIUM 6.5 CVE-2022-1830 The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers … Amazon Einzeltitellinks after 1.3.3 Fix from $1,6002022-06-20 MEDIUM 6.5 CVE-2022-1831 The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged … Wplite after 1.3.1 Fix from $1,6002022-06-20 MEDIUM 6.5 CVE-2022-1832 The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a… Capa Protect after 0.5.8.2 Fix from $1,6002022-06-20 MEDIUM 6.5 CVE-2022-1610 The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to mak… Seamless Donations 5.1.9+ Fix from $1,6002022-06-20 MEDIUM 6.5 CVE-2022-1630 The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in … Wp Email 2.69.0+ Fix from $1,6002022-06-20 MEDIUM 5.4 CVE-2022-1818 The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make… Multi Page Toolkit after 2.6 Fix from $1,6002022-06-20 MEDIUM 6.5 CVE-2022-1826 The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which could allow attackers to make a … Cross Linker after 3.0.1.9 Fix from $1,6002022-06-20 MEDIUM 6.5 CVE-2022-1827 The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to … Pdf24 Articles To Pdf after 4.2.2 Fix from $1,6002022-06-20 HIGH 8.8 CVE-2017-20062 A vulnerability was found in Elefant CMS 1.3.12-RC and classified as problematic. This issue affects some unknown processing. The manipulation leads … Elefant Cms No fix yet Fix from $1,9502022-06-20 MEDIUM 6.5 CVE-2022-30327 An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The web interface is vulnerable to CSRF. An attacker can change the pre-shared k… Tew 831dr Firmware No fix yet Fix from $1,6002022-06-16 MEDIUM 6.5 CVE-2022-30328 An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering … Tew 831dr Firmware Mitigation only Fix from $1,6002022-06-16 HIGH 8.8 CVE-2022-26173 JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attack… Jforum Mitigation only Fix from $1,9502022-06-16 MEDIUM 6.5 CVE-2022-31294 An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user account… Online Discussion Forum Site No fix yet Fix from $1,6002022-06-16 HIGH 8.8 CVE-2022-29450 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress. Admin Management Xtended after 2.4.4 Fix from $1,9502022-06-15 HIGH 8.8 CVE-2022-29437 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress. Image Slider By Nextcode after 1.1.2 Fix from $1,9502022-06-15