Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2021-24674 The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logg… Genie Wp Favicon after 0.5.2 Fix from $1,6002021-11-08 MEDIUM 6.5 CVE-2020-21139 EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin account… Ec Cloud E Commerce System No fix yet Fix from $1,6002021-11-04 MEDIUM 6.5 CVE-2021-34773 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Sess… Unified Communications Manager Mitigation only Fix from $1,6002021-11-04 HIGH 8.8 CVE-2020-23686 Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts. Ayacms No fix yet Fix from $1,9502021-11-02 HIGH 8.8 CVE-2021-29888 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize… Infosphere Information Server Patch available Fix from $1,9502021-11-02 HIGH 8.8 CVE-2021-24809 The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_be… Better Messages 1.9.9.41+ Fix from $1,9502021-11-01 MEDIUM 6.5 CVE-2020-36504 The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged … Wp Pro Quiz after 0.37 Fix from $1,6002021-11-01 MEDIUM 6.5 CVE-2020-36505 The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthentic… Delete All Comments Easily after 1.3 Fix from $1,6002021-11-01 MEDIUM 5.4 CVE-2021-24685 The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them… Flat Preloader 1.5.4+ Fix from $1,6002021-11-01 HIGH 8.8 CVE-2021-3901 firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) Firefly Iii after 5.6.2 Fix from $1,9502021-10-27 MEDIUM 6.5 CVE-2021-3900 firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) Firefly Iii after 5.6.2 Fix from $1,6002021-10-27 HIGH 8.8 CVE-2021-24487 The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and… St Daily Tip after 4.7 Fix from $1,9502021-10-25 MEDIUM 6.1 CVE-2021-24543 The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor sanitise or escape its 'Quote St… Jquery Reply To Comment after 1.31 Fix from $1,6002021-10-25 MEDIUM 6.5 CVE-2021-24779 The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF che… Wp Debugging 2.11.0+ Fix from $1,6002021-10-25 CRITICAL 9.6 CVE-2021-24884 The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could … Formidable Form Builder 4.09.05+ Fix from $2,3002021-10-25 HIGH 8.8 CVE-2021-20120 The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an … Arris Surfboard Sb8200 Firmware No fix yet Fix from $1,9502021-10-21 MEDIUM 6.5 CVE-2021-39126 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF)… Jira Data Center 8.5.10 / 8.13.1+ Fix from $1,6002021-10-21 HIGH 7.1 CVE-2021-34743 A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an extern… Webex Meetings Mitigation only Fix from $1,9502021-10-21 HIGH 8.0 CVE-2021-42097 GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain … Debian Linux 2.1.35+ Fix from $1,9502021-10-21 HIGH 8.8 CVE-2021-38480 InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submi… Ir615 Firmware Mitigation only Fix from $1,9502021-10-19 HIGH 8.8 CVE-2021-3858 snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) Snipe It 5.3.0+ Fix from $1,9502021-10-19 MEDIUM 5.7 CVE-2021-24752 Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authentic… Catch Scroll Progress Bar 1.4 / 1.6+ Fix from $1,6002021-10-18 MEDIUM 6.5 CVE-2021-24595 The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in… Wp Cookie Choice after 1.1.0 Fix from $1,6002021-10-18 MEDIUM 5.4 CVE-2021-24615 The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to ma… Wechat Reward after 1.7 Fix from $1,6002021-10-18 MEDIUM 6.5 CVE-2021-24642 The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or v… Scroll Banner after 1.0 Fix from $1,6002021-10-18 MEDIUM 6.5 CVE-2021-24675 The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is emb… One User Avatar 2.3.7+ Fix from $1,6002021-10-18 MEDIUM 6.5 CVE-2021-24735 The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin chan… Compact Wp Audio Player 1.9.7+ Fix from $1,6002021-10-18 MEDIUM 6.5 CVE-2021-39864 Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vul… Commerce after 2.3.7 Fix from $1,6002021-10-15 HIGH 8.8 CVE-2021-42228 A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html. Kindeditor after 4.1.12 Fix from $1,9502021-10-14 MEDIUM 6.5 CVE-2020-19964 A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account withou… Phpmywind No fix yet Fix from $1,6002021-10-14