Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2019-25064 A vulnerability was found in CoreHR Core Portal up to 27.0.7. It has been classified as problematic. Affected is an unknown function. The manipulatio… Corehr Core Portal after 27.0.7 Fix from $1,9502022-06-09 MEDIUM 6.5 CVE-2022-1422 The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin in… Discy 5.2+ Fix from $1,6002022-06-08 MEDIUM 6.5 CVE-2022-1424 The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to pe… Ask Me 6.8.2+ Fix from $1,6002022-06-08 MEDIUM 6.5 CVE-2022-1570 The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any … Files Download Delay 1.0.7+ Fix from $1,6002022-06-08 MEDIUM 5.4 CVE-2022-1577 The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow… Database Backup 2.5.2+ Fix from $1,6002022-06-08 MEDIUM 6.5 CVE-2020-36534 A vulnerability was found in easyii CMS. It has been classified as problematic. Affected is an unknown function of the file /admin/sign/out. The mani… Easyiicms No fix yet Fix from $1,6002022-06-07 HIGH 8.8 CVE-2022-29735 Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request. Entelitouch Firmware No fix yet Fix from $1,9502022-06-02 HIGH 8.8 CVE-2022-29647 An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. Mcms No fix yet Fix from $1,9502022-06-02 HIGH 8.8 CVE-2020-20971 Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index. Pbootcms No fix yet Fix from $1,9502022-06-02 MEDIUM 6.5 CVE-2022-22361 IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, … Business Automation Workflow after 21.0.3 Fix from $1,6002022-05-31 HIGH 7.5 CVE-2022-1589 The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its se… All In One Login 1.1.0+ Fix from $1,9502022-05-30 HIGH 8.8 CVE-2022-1611 The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable… Bulk Page Creator 1.1.4+ Fix from $1,9502022-05-30 MEDIUM 5.4 CVE-2022-0642 The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not s… Jivochat 1.3.5.4+ Fix from $1,6002022-05-30 HIGH 8.8 CVE-2021-34360 A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allo… Nas Proxy Server 1.4.2 / 1.4.3+ Fix from $1,9502022-05-26 HIGH 8.8 CVE-2022-29002 A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin… Xxl Job No fix yet Fix from $1,9502022-05-23 HIGH 8.8 CVE-2022-30014 Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account. Simple Food Website Mitigation only Fix from $1,9502022-05-23 HIGH 8.8 CVE-2022-29427 Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress. Disable Right Click For Wp after 1.1.6 Fix from $1,9502022-05-20 MEDIUM 6.1 CVE-2022-29430 Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin <= 4.0 at WordPress via Cross-Site Request Forgery (CSRF). Vulnerable parameter… Png To Jpg after 4.0 Fix from $1,6002022-05-20 MEDIUM 5.4 CVE-2022-29431 Cross-Site Request Forgery (CSRF) vulnerability in KubiQ CPT base plugin <= 5.8 at WordPress allows an attacker to delete the CPT base. Cpt Base after 5.8 Fix from $1,6002022-05-20 HIGH 8.8 CVE-2022-28992 A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request. Online Banquet Booking System No fix yet Fix from $1,9502022-05-20 MEDIUM 6.5 CVE-2022-28921 A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on t… Blogengine.net No fix yet Fix from $1,6002022-05-18 HIGH 8.8 CVE-2022-22778 The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability tha… Businessconnect Trading Community Management 6.1.1+ Fix from $1,9502022-05-18 HIGH 8.8 CVE-2022-27632 Cross-site request forgery (CSRF) vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT light RPC-M5C [En… Watch Boot Nino Rpc M2c Firmware after 1.20a Fix from $1,9502022-05-18 MEDIUM 5.4 CVE-2022-29435 Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress allows an attacker to del… Code Snippets Extended after 1.4.7 Fix from $1,6002022-05-17 MEDIUM 6.1 CVE-2022-29436 Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Reques… Code Snippets Extended after 1.4.7 Fix from $1,6002022-05-17 HIGH 8.8 CVE-2022-29429 Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery. Code Snippets Extended after 1.4.7 Fix from $1,9502022-05-17 HIGH 8.8 CVE-2022-30969 A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code… Autocomplete Parameter after 1.1 Fix from $1,9502022-05-17 HIGH 8.8 CVE-2022-30972 A cross-site request forgery (CSRF) vulnerability in Jenkins Storable Configs Plugin 1.0 and earlier allows attackers to have Jenkins parse a local X… Storage Configs after 1.0 Fix from $1,9502022-05-17 HIGH 8.8 CVE-2022-30958 A cross-site request forgery (CSRF) vulnerability in Jenkins SSH Plugin 2.6.1 and earlier allows attackers to connect to an attacker-specified SSH se… Ssh after 2.6.1 Fix from $1,9502022-05-17 MEDIUM 6.5 CVE-2022-30953 A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specifie… Blue Ocean after 1.25.3 Fix from $1,6002022-05-17