Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.1 CVE-2021-24823 The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow atta… Support Board 3.3.6+ Fix from $1,9502022-02-28 HIGH 8.8 CVE-2022-24342 In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible. Teamcity 2021.2.1+ Fix from $1,9502022-02-25 HIGH 8.8 CVE-2022-24947 Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2… Jspwiki 2.11.2+ Fix from $1,9502022-02-25 HIGH 8.8 CVE-2021-4030 A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands… Nbg6816 Firmware 1.00+ Fix from $1,9502022-02-24 HIGH 8.8 CVE-2022-23983 Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protection & No Right Click WordPress… Wp Content Copy Protection \& No Right Click after 3.4.4 Fix from $1,9502022-02-21 HIGH 8.8 CVE-2022-0134 The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make l… Anycomment 0.2.18+ Fix from $1,9502022-02-21 MEDIUM 6.5 CVE-2021-45007 Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NO… Plesk No fix yet Fix from $1,6002022-02-20 HIGH 8.8 CVE-2022-25241 In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF). Filecloud 21.3.0.18447+ Fix from $1,9502022-02-16 HIGH 8.8 CVE-2022-25242 In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF). Filecloud 21.3.0.18447+ Fix from $1,9502022-02-16 MEDIUM 6.5 CVE-2021-46252 A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account reques… Scratch Confirmaccount V3 2022-01-04+ Fix from $1,6002022-02-15 HIGH 8.8 CVE-2022-25205 A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified d… Dbcharts after 0.5.2 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25207 A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP reque… Chef Sinatra after 1.20 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25212 A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web … Swamp after 1.2.6 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25192 A cross-site request forgery (CSRF) vulnerability in Jenkins Snow Commander Plugin 1.10 and earlier allows attackers to connect to an attacker-specif… Snow Commander after 1.10 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25194 A cross-site request forgery (CSRF) vulnerability in Jenkins autonomiq Plugin 1.15 and earlier allows attackers to connect to an attacker-specified U… Autonomiq after 1.15 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25198 A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to connect to an attacker-specifie… Scp Publisher after 1.8 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25200 A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specifi… Checkmarx after 2022.1.2 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-23384 YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add Yzmcms No fix yet Fix from $1,9502022-02-15 MEDIUM 6.5 CVE-2021-43941 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa an… Jira Data Center 8.13.5 / 8.20.3+ Fix from $1,6002022-02-15 MEDIUM 5.4 CVE-2021-24446 The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make… Remove Footer Credit 1.0.6+ Fix from $1,6002022-02-14 HIGH 8.8 CVE-2021-46366 An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Fo… Magnolia Cms 6.2.4+ Fix from $1,9502022-02-11 MEDIUM 6.1 CVE-2020-13673 The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivil… Entity Embed Patch available Fix from $1,6002022-02-11 MEDIUM 6.5 CVE-2020-13674 The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to p… Drupal 8.9.19 / 9.1.13+ Fix from $1,6002022-02-11 HIGH 8.8 CVE-2022-22808 A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cro… Hmibscea53d1edb Firmware 4.0.0.13+ Fix from $1,9502022-02-09 HIGH 8.1 CVE-2022-22811 A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of t… Spacelynk Firmware after 2.6.2 Fix from $1,9502022-02-09 HIGH 8.8 CVE-2021-22954 A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users. Concrete Cms 9.0+ Fix from $1,9502022-02-09 HIGH 8.8 CVE-2022-21703 Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability whic… Grafana 3.0 / 7.5.15+ Fix from $1,9502022-02-08 HIGH 8.8 CVE-2021-45326 Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST… Gitea 1.5.2+ Fix from $1,9502022-02-08 MEDIUM 6.5 CVE-2022-0505 Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-08 HIGH 7.1 CVE-2021-25108 The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, al… Country Blocker 2.26.6+ Fix from $1,9502022-02-07