Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2021-36887 Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR Wor… Tarteaucitron.js Cookies Legislation \& Gdpr after 1.5.4 Fix from $1,9502021-12-20 HIGH 8.8 CVE-2021-4131 livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) Live Helper Chat 2.0+ Fix from $1,9502021-12-18 HIGH 8.8 CVE-2021-4130 snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) Snipe It 5.3.6+ Fix from $1,9502021-12-18 MEDIUM 6.5 CVE-2021-26800 Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allow… User Management System In Php Stored Procedure Mitigation only Fix from $1,6002021-12-16 HIGH 8.8 CVE-2021-41260 Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check … Galette 0.9.6+ Fix from $1,9502021-12-16 MEDIUM 6.5 CVE-2021-4123 livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) Live Helper Chat 2.0+ Fix from $1,6002021-12-16 HIGH 8.8 CVE-2021-45017 Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a goog… Catfish Cms after 6.3.0 Fix from $1,9502021-12-15 CRITICAL 9.0 CVE-2021-24922 The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, w… Pixel Cat 2.6.2+ Fix from $2,3002021-12-13 HIGH 8.0 CVE-2021-24945 The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX acti… Like Button Rating 2.6.38+ Fix from $1,9502021-12-13 MEDIUM 6.5 CVE-2021-24784 The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logge… Wp Admin Logo Changer after 1.0 Fix from $1,6002021-12-13 MEDIUM 6.5 CVE-2021-24795 The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could all… Filter Portfolio Gallery after 1.5 Fix from $1,6002021-12-13 MEDIUM 6.5 CVE-2021-4033 kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) Kimai 2 1.16.7+ Fix from $1,6002021-12-09 HIGH 8.8 CVE-2020-19682 A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php. Zzzcms No fix yet Fix from $1,9502021-12-09 MEDIUM 6.5 CVE-2021-4049 livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) Live Helper Chat 2.0+ Fix from $1,6002021-12-07 HIGH 8.8 CVE-2021-31631 b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to … B2evolution Cms No fix yet Fix from $1,9502021-12-06 HIGH 8.8 CVE-2021-35242 Serv-U server responds with valid CSRFToken when the request contains only Session. Serv U 15.2.5+ Fix from $1,9502021-12-06 HIGH 8.0 CVE-2021-24914 The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX act… Tawk.to Live Chat 0.6.0+ Fix from $1,9502021-12-06 HIGH 8.8 CVE-2021-29756 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execu… Cognos Analytics 11.1.7+ Fix from $1,9502021-12-03 CRITICAL 9.6 CVE-2015-20105 The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admi… Clickbank Affiliate Ads after 1.20 Fix from $2,3002021-12-02 MEDIUM 6.8 CVE-2021-3944 bookstack is vulnerable to Cross-Site Request Forgery (CSRF) Bookstack 21.11+ Fix from $1,6002021-12-02 HIGH 8.8 CVE-2021-44227 In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin passwo… Debian Linux 2.1.38+ Fix from $1,9502021-12-02 HIGH 8.8 CVE-2021-43137 Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile… Hostel Management System No fix yet Fix from $1,9502021-12-01 MEDIUM 6.5 CVE-2021-3993 showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Showdoc 2.9.13+ Fix from $1,6002021-12-01 HIGH 8.8 CVE-2021-4017 showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Showdoc 2.9.13+ Fix from $1,9502021-12-01 HIGH 8.8 CVE-2021-20860 Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior,… Wrc 1167gst2 Firmware after 2.11 Fix from $1,9502021-12-01 HIGH 8.8 CVE-2021-20851 Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker… Browser And Operating System Finder 1.2+ Fix from $1,9502021-12-01 HIGH 8.8 CVE-2021-42358 The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php fil… Contact Form With Captcha after 1.6.2 Fix from $1,9502021-11-29 HIGH 8.8 CVE-2021-42364 The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/st… Stetic after 1.0.6 Fix from $1,9502021-11-29 MEDIUM 5.4 CVE-2021-24822 The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to a… Stylish Cost Calculator 7.0.4+ Fix from $1,6002021-11-29 MEDIUM 6.1 CVE-2021-43777 Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly … Redash after 10.0.0 Fix from $1,6002021-11-24