Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2026-26317 OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without expl… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 MEDIUM 5.4 CVE-2026-27050 Cross-Site Request Forgery (CSRF) vulnerability in ThimPress RealPress realpress allows Cross Site Request Forgery.This issue affects RealPress: from… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-25422 Cross-Site Request Forgery (CSRF) vulnerability in Themes4WP Popularis Extra popularis-extra allows Cross Site Request Forgery.This issue affects Pop… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-25337 Cross-Site Request Forgery (CSRF) vulnerability in wpcoachify Coachify coachify allows Cross Site Request Forgery.This issue affects Coachify: from n… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-25322 Cross-Site Request Forgery (CSRF) vulnerability in PublishPress PublishPress Revisions revisionary allows Cross Site Request Forgery.This issue affec… Mitigation only Fix from $1,6002026-02-19 HIGH 8.8 CVE-2025-12821 The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is due to missing or incorrect … Mitigation only Fix from $1,9502026-02-19 HIGH 8.2 CVE-2019-25359 SD.NET RIM versions before 4.7.3c contain a SQL injection vulnerability that allows attackers to inject malicious SQL statements through POST paramet… No fix yet Fix from $1,9502026-02-18 MEDIUM 6.5 CVE-2025-70062 PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fai… Hospital Management System No fix yet Fix from $1,6002026-02-18 MEDIUM 6.5 CVE-2025-27904 IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to cross-site request forgery w… Db2 Recovery Expert Patch available Fix from $1,6002026-02-17 MEDIUM 6.5 CVE-2025-36018 IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an attacker to execute malicious an… Concert 2.2.0+ Fix from $1,6002026-02-17 MEDIUM 5.4 CVE-2026-26075 FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisiti… Fastgpt 4.14.7+ Fix from $1,6002026-02-12 CRITICAL 9.0 CVE-2025-69634 Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.… Mitigation only Fix from $2,3002026-02-12 HIGH 8.8 CVE-2020-37158 AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password reco… Avideo No fix yet Fix from $1,9502026-02-11 MEDIUM 6.5 CVE-2026-2317 Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted H… Chrome 145.0.7632.45+ Fix from $1,6002026-02-11 HIGH 8.0 CVE-2026-24885 Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in t… Kanboard 1.2.50+ Fix from $1,9502026-02-10 HIGH 8.8 CVE-2026-25812 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests … Placipy Mitigation only Fix from $1,9502026-02-09 MEDIUM 5.4 CVE-2025-66595 A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product is vulnerable to Cross-Site Request Forgery (… Fast\/tools Mitigation only Fix from $1,6002026-02-09 MEDIUM 5.3 CVE-2020-37106 Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user account roles without authen… No fix yet Fix from $1,6002026-02-07 MEDIUM 5.3 CVE-2020-37144 Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a craft… No fix yet Fix from $1,6002026-02-05 HIGH 8.8 CVE-2020-37149 Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authen… Ew 7438rpn Mini Firmware No fix yet Fix from $1,9502026-02-05 HIGH 8.8 CVE-2025-68722 Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface thro… Axigen Mail Server 10.5.57 / 10.6.26+ Fix from $1,9502026-02-05 MEDIUM 5.9 CVE-2026-25151 Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP r… Qwik 1.19.0+ Fix from $1,6002026-02-03 HIGH 7.1 CVE-2026-25155 Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect p… Qwik 1.12.0+ Fix from $1,9502026-02-03 MEDIUM 5.3 CVE-2020-37091 Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authen… No fix yet Fix from $1,6002026-02-03 MEDIUM 6.5 CVE-2026-24434 Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management … Ac7 Firmware after 03.03.03.01 Fix from $1,6002026-02-03 MEDIUM 6.5 CVE-2026-24666 The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Cross-Site Request Forgery … Open Eclass Platform 4.2+ Fix from $1,6002026-02-03 MEDIUM 5.4 CVE-2026-25024 Cross-Site Request Forgery (CSRF) vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Cross Site Request Forgery.This issue af… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.4 CVE-2026-24986 Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Req… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.4 CVE-2026-1447 The Mail Mint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19.2. This is due to missing n… Mitigation only Fix from $1,6002026-02-03 HIGH 8.1 CVE-2026-25221 PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, the OAuth 2.0 implementation for GitHub and Google login provi… Polarlearn Patch available Fix from $1,9502026-02-02