Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2022-1407 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does n… Hotel Booking Engine \& Pms 1.5.8+ Fix from $1,6002022-05-16 MEDIUM 6.1 CVE-2022-1418 The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape … Social Stickers after 2.2.9 Fix from $1,6002022-05-16 MEDIUM 6.5 CVE-2021-27758 There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and s… Bigfix Inventory 10.0.7.0+ Fix from $1,6002022-05-06 MEDIUM 6.5 CVE-2021-27759 This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intent… Bigfix Inventory 10.0.7.0+ Fix from $1,6002022-05-06 HIGH 8.8 CVE-2022-25778 Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user sess… Gatemanager 4250 Firmware 9.7.622134021+ Fix from $1,9502022-05-04 HIGH 8.8 CVE-2022-0916 An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF at… Options 9.60.87+ Fix from $1,9502022-05-03 MEDIUM 6.5 CVE-2022-0191 The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to ma… Ad Invalid Click Protector 1.2.7+ Fix from $1,6002022-05-02 HIGH 8.8 CVE-2022-0952EPSS 11% The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does … Sitemap 1.0.36+ Fix from $1,9502022-05-02 HIGH 8.0 CVE-2022-23904 Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to … Auctionworx after 3.1 Fix from $1,9502022-05-02 MEDIUM 5.4 CVE-2022-29414 Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows atta… Subscribe To Comments Reloaded after 211130 Fix from $1,6002022-04-29 HIGH 8.8 CVE-2022-29451 Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows at… Rara One Click Demo Import 1.3.0+ Fix from $1,9502022-04-29 HIGH 8.8 CVE-2021-43937 Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intenti… Scada Server No fix yet Fix from $1,9502022-04-29 HIGH 8.8 CVE-2022-29555 The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking. Mender 3.2.2+ Fix from $1,9502022-04-28 MEDIUM 5.4 CVE-2022-29412 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers to delete cache, delete … Hermit after 3.1.6 Fix from $1,6002022-04-28 MEDIUM 6.1 CVE-2022-29413 Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress via &title … Hermit after 3.1.6 Fix from $1,6002022-04-28 MEDIUM 6.1 CVE-2022-27860 Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress. Footer Text after 2.0.3 Fix from $1,6002022-04-28 HIGH 8.8 CVE-2022-28892 Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too eas… Mahara 20.10.5 / 21.04.4+ Fix from $1,9502022-04-28 HIGH 7.5 CVE-2022-24879 Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) t… Shopware 5.7.9+ Fix from $1,9502022-04-28 MEDIUM 6.5 CVE-2022-27374 Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot. Ax12 Firmware No fix yet Fix from $1,6002022-04-25 MEDIUM 6.5 CVE-2022-27375 Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet. Ax12 Firmware No fix yet Fix from $1,6002022-04-25 MEDIUM 5.4 CVE-2022-0398 The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links… Thirstyaffiliates Affiliate Link Manager 3.10.5+ Fix from $1,6002022-04-25 HIGH 8.8 CVE-2022-27340 MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges an… Mcms No fix yet Fix from $1,9502022-04-22 HIGH 8.8 CVE-2021-38886 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un… Cognos Analytics Patch available Fix from $1,9502022-04-22 HIGH 8.8 CVE-2021-32929 All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user. Gps Tracker No fix yet Fix from $1,9502022-04-22 MEDIUM 6.8 CVE-2022-20787 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Mana… Unified Communications Manager 12.5 / 14su1+ Fix from $1,6002022-04-21 HIGH 8.8 CVE-2022-27629 Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership' versions prior to 1.9.… Micropayments 1.9.6+ Fix from $1,9502022-04-20 HIGH 8.8 CVE-2021-4096 The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for… Fancy Product Designer after 4.7.5 Fix from $1,9502022-04-19 HIGH 8.8 CVE-2022-28108EPSS 12% Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data,… Selenium Grid 4.0.0+ Fix from $1,9502022-04-19 MEDIUM 5.4 CVE-2022-1112 The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape th… Autolinks after 1.0.1 Fix from $1,6002022-04-18 CRITICAL 9.8 CVE-2022-1020EPSS 26% The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update… Woo Product Table 3.1.2+ Fix from $2,3002022-04-18