Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.0 CVE-2022-0154 An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all v… GitLab 14.4.5 / 14.5.3+ Fix from $1,9502022-01-18 HIGH 8.8 CVE-2022-0215 The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable … Login\/signup Popup after 2.5.1 Fix from $1,9502022-01-18 HIGH 8.8 CVE-2021-43353 The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page f… Crisp 0.32+ Fix from $1,9502022-01-18 HIGH 8.8 CVE-2021-4164 calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) Calibre Web 0.6.15+ Fix from $1,9502022-01-17 HIGH 8.8 CVE-2022-0180 Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authenticati… Quiz And Survey Master 7.3.7+ Fix from $1,9502022-01-17 MEDIUM 6.5 CVE-2022-0231 livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) Live Helper Chat after 3.91 Fix from $1,6002022-01-14 HIGH 8.8 CVE-2021-23227 Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions. Php Everywhere after 2.0.2 Fix from $1,9502022-01-13 HIGH 8.8 CVE-2022-0196 phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) Fedora 10.8.0+ Fix from $1,9502022-01-13 HIGH 8.8 CVE-2022-0197 phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) Fedora 10.8.0+ Fix from $1,9502022-01-13 HIGH 7.1 CVE-2022-20619 A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect… Bitbucket Branch Source after 2.9.10 Fix from $1,9502022-01-12 MEDIUM 5.4 CVE-2022-23115 Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Overall/Read access to retrieve… Batch Task after 1.19 Fix from $1,6002022-01-12 HIGH 8.8 CVE-2021-41597 SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included … Suitecrm 7.10.35 / 7.12.2+ Fix from $1,9502022-01-12 HIGH 8.8 CVE-2021-37198 A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web … Comos 10.3.3.3+ Fix from $1,9502022-01-11 HIGH 8.8 CVE-2021-25051 The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well … Modal Window 5.2.2+ Fix from $1,9502022-01-10 HIGH 8.8 CVE-2021-25052 The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as w… Button Generator 2.3.3+ Fix from $1,9502022-01-10 HIGH 8.8 CVE-2021-25053 The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as w… Wp Coder 2.5.2+ Fix from $1,9502022-01-10 CRITICAL 9.8 CVE-2021-25032EPSS 7% The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation … Capabilities 2.3.1+ Fix from $2,3002022-01-10 HIGH 8.8 CVE-2021-46147 An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF. Mediawiki 1.35.5 / 1.36.3+ Fix from $1,9502022-01-10 HIGH 8.8 CVE-2021-34086 In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver ho… Ultimaker S3 Firmware after 6.3 Fix from $1,9502022-01-10 HIGH 8.8 CVE-2021-20165 Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigati… Tew 827dru Firmware No fix yet Fix from $1,9502021-12-30 MEDIUM 6.5 CVE-2020-29292 iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP ad… Wrd12en Firmware Mitigation only Fix from $1,6002021-12-30 HIGH 8.8 CVE-2020-21236 A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtai… Damicms No fix yet Fix from $1,9502021-12-27 HIGH 8.8 CVE-2020-20945 A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator… Qibosoft No fix yet Fix from $1,9502021-12-27 MEDIUM 5.4 CVE-2021-24988 The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which… Wp Rss Aggregator 4.19.3+ Fix from $1,6002021-12-27 HIGH 8.8 CVE-2021-4168 showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Showdoc 2.9.15+ Fix from $1,9502021-12-26 HIGH 8.0 CVE-2020-20593 A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account. Rockoa No fix yet Fix from $1,9502021-12-22 MEDIUM 6.5 CVE-2020-20595 A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add. Opms No fix yet Fix from $1,6002021-12-22 HIGH 8.8 CVE-2021-36886 Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9). Contact Form 7 Database Addon 1.2.6.1+ Fix from $1,9502021-12-22 MEDIUM 6.5 CVE-2021-43156 In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book. Online Book Store Project In Php No fix yet Fix from $1,6002021-12-22 HIGH 7.5 CVE-2021-24981 The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell upl… Directorist 7.0.6.2+ Fix from $1,9502021-12-21