Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2021-20842 Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Adminis… Ec Cube after 2.17.1 Fix from $1,6002021-11-24 HIGH 8.8 CVE-2021-20845 Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authenti… Unlimited Sitemap Generator 8.2+ Fix from $1,9502021-11-24 HIGH 8.8 CVE-2021-20846 Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack… Push Notifications For Wordpress 6.0.1+ Fix from $1,9502021-11-24 HIGH 8.1 CVE-2021-24641 The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in … Images To Webp 1.9+ Fix from $1,9502021-11-23 MEDIUM 5.7 CVE-2021-24703 The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any aut… Download Plugin 1.6.1+ Fix from $1,6002021-11-23 HIGH 8.8 CVE-2021-43559 A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" fun… Moodle 3.9.11 / 3.10.8+ Fix from $1,9502021-11-22 HIGH 8.8 CVE-2021-34358 We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later Qmailagent 3.0.2+ Fix from $1,9502021-11-20 MEDIUM 5.4 CVE-2021-39198 OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an a… Client Relationship Management after 4.2.5 Fix from $1,6002021-11-19 HIGH 8.8 CVE-2021-44036 Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import. Team Password Manager 10.135.236+ Fix from $1,9502021-11-19 HIGH 8.8 CVE-2021-39353 The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form functi… Easy Registration Forms after 2.1.1 Fix from $1,9502021-11-19 MEDIUM 6.5 CVE-2021-3976 kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) Kimai 2 1.16.2+ Fix from $1,6002021-11-19 HIGH 8.8 CVE-2021-36908 Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions. Wp Reset Pro 5.99+ Fix from $1,9502021-11-18 HIGH 8.8 CVE-2021-41274 solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devi… Solidus Auth Devise 2.5.4+ Fix from $1,9502021-11-17 HIGH 8.8 CVE-2021-41275 spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by u… Spree Auth Devise 4.4.1+ Fix from $1,9502021-11-17 MEDIUM 6.5 CVE-2021-24852 The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make … Mousewheel Smooth Scroll 5.7+ Fix from $1,6002021-11-17 MEDIUM 6.5 CVE-2021-24802 The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor … Colorful Categories 2.0.15+ Fix from $1,6002021-11-17 HIGH 8.8 CVE-2021-24804 The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin … Simple Jwt Login 3.2.1+ Fix from $1,9502021-11-17 HIGH 8.8 CVE-2021-25965 In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an … Calibre Web after 0.6.13 Fix from $1,9502021-11-16 HIGH 8.1 CVE-2021-25976 In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the ma… Piranha Cms after 9.2 Fix from $1,9502021-11-16 MEDIUM 6.5 CVE-2021-3683 showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Showdoc after 2.9.12 Fix from $1,6002021-11-13 MEDIUM 5.4 CVE-2021-3775 showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Showdoc after 2.9.12 Fix from $1,6002021-11-13 MEDIUM 5.4 CVE-2021-3776 showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Showdoc after 2.9.12 Fix from $1,6002021-11-13 HIGH 8.8 CVE-2020-21141 iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add. Icms No fix yet Fix from $1,9502021-11-12 MEDIUM 6.5 CVE-2020-28137 Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the rout… Platinum 4410 Firmware No fix yet Fix from $1,6002021-11-10 HIGH 8.8 CVE-2021-41426 Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm. Smart Box Firmware No fix yet Fix from $1,9502021-11-10 MEDIUM 6.5 CVE-2021-40518 Airangel HSMX Gateway devices through 5.2.04 allow CSRF. Hsmx App 25 Firmware after 5.2.04 Fix from $1,6002021-11-10 HIGH 7.6 CVE-2021-41372 A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing H… Power Bi Report Server Patch available Fix from $1,9502021-11-10 MEDIUM 6.5 CVE-2021-24766 The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which co… 404 To 301 3.0.9+ Fix from $1,6002021-11-08 MEDIUM 6.5 CVE-2021-24767 The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which coul… Redirect 404 Error Page To Homepage Or Custom Page With Logs 1.7.9+ Fix from $1,6002021-11-08 HIGH 8.8 CVE-2021-24626 The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, s… Chameleon Css after 1.2 Fix from $1,9502021-11-08