Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2022-23975 Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin. Access Demo Importer after 1.0.7 Fix from $1,6002022-04-18 HIGH 8.1 CVE-2022-23976 Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media). Access Demo Importer after 1.0.7 Fix from $1,9502022-04-18 HIGH 8.8 CVE-2022-28109 Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The impact is: execute arbitrary c… Selenium Grid 4.0.0+ Fix from $1,9502022-04-15 MEDIUM 6.5 CVE-2022-20735 A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a c… Catalyst Sd Wan Manager 20.6.1+ Fix from $1,6002022-04-15 MEDIUM 6.5 CVE-2022-26589 A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages. Pluck Mitigation only Fix from $1,6002022-04-13 HIGH 8.8 CVE-2022-29050 A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over FTP Plugin 1.16 and earlier allows attackers to connect to an FTP server us… Publish Over Ftp after 1.16 Fix from $1,9502022-04-12 MEDIUM 6.1 CVE-2021-36914 Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Manager (WordPress plugin) <= 1.… Calderawp License Manager after 1.2.11 Fix from $1,6002022-04-12 HIGH 8.1 CVE-2022-0141 The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor d… Visual Form Builder 3.0.6+ Fix from $1,9502022-04-12 HIGH 8.8 CVE-2022-25754 A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC… Scalance X302 7eec Firmware 4.1.4+ Fix from $1,9502022-04-12 MEDIUM 6.5 CVE-2022-0914 The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admi… Export All Urls 4.3+ Fix from $1,6002022-04-11 HIGH 8.8 CVE-2021-32156 A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. Webmin No fix yet Fix from $1,9502022-04-11 HIGH 8.8 CVE-2021-32159 A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature. Webmin No fix yet Fix from $1,9502022-04-11 HIGH 8.8 CVE-2021-32162 A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature. Webmin No fix yet Fix from $1,9502022-04-11 HIGH 8.8 CVE-2022-26180 qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI. Qdpm No fix yet Fix from $1,9502022-04-08 MEDIUM 6.5 CVE-2022-26588 A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.ph… Icehrm No fix yet Fix from $1,6002022-04-08 HIGH 8.8 CVE-2020-4668 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forger… Sterling B2b Integrator after 6.1.0.3 Fix from $1,9502022-04-08 HIGH 8.1 CVE-2022-20774 A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauth… Ip Phone 6871 Firmware 11.3.5+ Fix from $1,9502022-04-06 HIGH 8.1 CVE-2021-41245 Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't… Itop 2.7.6+ Fix from $1,9502022-04-05 MEDIUM 6.5 CVE-2022-0830 The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as … Formbuilder after 1.08 Fix from $1,6002022-04-04 HIGH 7.4 CVE-2022-0088 Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3. Yourls 1.8.3+ Fix from $1,9502022-04-03 HIGH 8.8 CVE-2021-44312 An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a… Firmware Analysis And Comparison Tool No fix yet Fix from $1,9502022-03-30 HIGH 8.8 CVE-2022-27432 A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading… Pluck No fix yet Fix from $1,9502022-03-30 HIGH 8.8 CVE-2022-28150 A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners a… Job And Node Ownership after 0.13.0 Fix from $1,9502022-03-29 HIGH 8.8 CVE-2022-28136 A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect … Jiratestresultreporter after 165.v817928553942 Fix from $1,9502022-03-29 MEDIUM 6.5 CVE-2022-28143 A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connect to an attacker-specified ho… Proxmox after 0.7.0 Fix from $1,6002022-03-29 HIGH 8.8 CVE-2022-0427 Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitra… GitLab 14.5.4 / 14.6.4+ Fix from $1,9502022-03-28 HIGH 8.8 CVE-2022-0499 The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any… Sermon Browser after 0.45.22 Fix from $1,9502022-03-28 HIGH 8.8 CVE-2022-0770 The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's coo… Translate Wordpress With Gtranslate 2.9.9+ Fix from $1,9502022-03-28 MEDIUM 5.3 CVE-2021-24978 The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_aj… Osmapper after 2.1.5 Fix from $1,6002022-03-28 HIGH 8.8 CVE-2022-25523 TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request. Typesetter Mitigation only Fix from $1,9502022-03-25