Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.1 CVE-2021-46426 phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality. Phpipam Patch available Fix from $1,6002022-03-25 HIGH 8.8 CVE-2022-25268 Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems. Passwork 4.6.13+ Fix from $1,9502022-03-23 MEDIUM 5.4 CVE-2022-25608 Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into u… Yoo Slider after 2.0.0 Fix from $1,6002022-03-23 MEDIUM 6.5 CVE-2021-43737 An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password. Xiaohuanxiong Cms No fix yet Fix from $1,6002022-03-23 HIGH 8.8 CVE-2021-43738 An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account. Xiaohuanxiong Cms No fix yet Fix from $1,9502022-03-23 HIGH 8.8 CVE-2021-40662 A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a… Chamilo Patch available Fix from $1,9502022-03-21 HIGH 8.8 CVE-2022-23349 BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF). Bigant Server Mitigation only Fix from $1,9502022-03-21 MEDIUM 6.5 CVE-2022-0681 The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make… Simple Membership 4.1.0+ Fix from $1,6002022-03-21 HIGH 8.1 CVE-2022-0229 The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMet… Google Authenticator 5.5+ Fix from $1,9502022-03-21 HIGH 8.0 CVE-2021-24905 The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX act… Advanced Cf7 Db 1.8.7+ Fix from $1,9502022-03-21 HIGH 8.8 CVE-2022-24235 A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code v… Aria No fix yet Fix from $1,9502022-03-21 HIGH 8.8 CVE-2022-27226EPSS 31% A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration pa… Ru21 Firmware after 2022-03-16 Fix from $1,9502022-03-19 HIGH 8.8 CVE-2022-27204 A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to … Extended Choice Parameter after 346.vd87693c5a_86c Fix from $1,9502022-03-15 MEDIUM 6.5 CVE-2022-27210 A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an … Kubernetes Continuous Deploy after 2.3.1 Fix from $1,6002022-03-15 HIGH 8.0 CVE-2022-27198 A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Ove… Cloudbees Aws Credentials 1.28.2+ Fix from $1,9502022-03-15 HIGH 8.8 CVE-2022-22346 IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to exec… Spectrum Protect Operations Center 8.1.14.000+ Fix from $1,9502022-03-14 HIGH 8.8 CVE-2021-45886 An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weaken… X\/p Messenger No fix yet Fix from $1,9502022-03-13 HIGH 8.8 CVE-2022-25600 Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (version… Wp Maps 4.2.4+ Fix from $1,9502022-03-11 HIGH 8.8 CVE-2022-0439 The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_r… Email Subscribers \& Newsletters 5.3.2+ Fix from $1,9502022-03-07 MEDIUM 6.5 CVE-2022-0445 The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when reset… Wordpress Real Cookie Banner 2.14.2+ Fix from $1,6002022-03-07 MEDIUM 6.5 CVE-2021-25098 The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a lo… Easy Pricing Tables 3.1.3+ Fix from $1,6002022-03-07 HIGH 8.8 CVE-2020-18326 Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a re… Subrion Cms Mitigation only Fix from $1,9502022-03-04 MEDIUM 5.0 CVE-2021-44321 Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the invento… Mini Inventory And Sales Management System No fix yet Fix from $1,6002022-03-04 MEDIUM 6.5 CVE-2022-23052 PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, … Petereport No fix yet Fix from $1,6002022-03-03 HIGH 8.8 CVE-2022-24712 CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attacker… Codeigniter 4.1.9+ Fix from $1,9502022-02-28 CRITICAL 9.6 CVE-2021-25010 The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arb… Post Snippets 3.1.4+ Fix from $2,3002022-02-28 MEDIUM 5.7 CVE-2021-25011 The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which co… Wp Google Map 1.8.1+ Fix from $1,6002022-02-28 MEDIUM 6.5 CVE-2021-25081 The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attacker… Wp Google Map 1.8.4+ Fix from $1,6002022-02-28 HIGH 8.8 CVE-2021-24704 In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query… Orange Form after 1.0 Fix from $1,9502022-02-28 HIGH 8.8 CVE-2021-24803 The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a… Core Tweaks Wp Setup after 4.1 Fix from $1,9502022-02-28