Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2021-32774 DataDump is a MediaWiki extension that provides dumps of wikis. Prior to commit 67a82b76e186925330b89ace9c5fd893a300830b, DataDump had no protection … Datadump 2021-07-07+ Fix from $1,6002021-07-20 MEDIUM 6.5 CVE-2020-4675 IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and … Infosphere Master Data Management Server Mitigation only Fix from $1,6002021-07-16 MEDIUM 6.5 CVE-2020-18151 Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account. Thinkcmf No fix yet Fix from $1,6002021-07-14 MEDIUM 6.5 CVE-2020-27379 Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 . The CSRF token is not being validated … Booking Core Mitigation only Fix from $1,6002021-07-14 HIGH 8.8 CVE-2021-20781 Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1.2.8 and versions prior to v.2… Wordpress Meta Data And Taxonomies Filter 1.2.8 / 2.2.8+ Fix from $1,9502021-07-14 HIGH 8.8 CVE-2021-20782 Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authenticat… Software License Manager 4.4.6+ Fix from $1,9502021-07-14 MEDIUM 6.1 CVE-2021-24434 The Glass WordPress plugin through 1.3.2 does not sanitise or escape its "Glass Pages" setting before outputting in a page, leading to a Stored Cross… Glass after 1.3.2 Fix from $1,6002021-07-12 HIGH 8.8 CVE-2020-4938 IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions … Mq Appliance 9.1.0.8 / 9.2.0.2+ Fix from $1,9502021-07-12 HIGH 8.8 CVE-2021-34620 The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Priv… Contact Form 3.6.67+ Fix from $1,9502021-07-07 MEDIUM 6.5 CVE-2021-22224 A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacke… GitLab 13.12.6 / 14.0.2+ Fix from $1,6002021-07-07 HIGH 8.8 CVE-2021-20779 Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers t… Wordpress Email Template Designer 3.0.8+ Fix from $1,9502021-07-07 HIGH 8.8 CVE-2021-20780 Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote attackers to hijack the authent… Wordpress Currency Switcher after 1.1.6 Fix from $1,9502021-07-07 MEDIUM 5.4 CVE-2021-24388 In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields th… Vikrentcar Car Rental Management System 1.1.7+ Fix from $1,6002021-07-06 MEDIUM 5.7 CVE-2021-32730 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability e… Xwiki 12.10.5+ Fix from $1,6002021-07-01 MEDIUM 6.5 CVE-2021-21675 A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or hav… Requests after 2.2.12 Fix from $1,6002021-06-30 HIGH 8.8 CVE-2021-20102 Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place. Machform 16+ Fix from $1,9502021-06-29 HIGH 8.8 CVE-2020-18648 Cross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component "JuQingCMS_v1.0/admin/index.ph… Juqingcms No fix yet Fix from $1,9502021-06-22 HIGH 8.8 CVE-2021-34244 A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts or change u… Icehrm No fix yet Fix from $1,9502021-06-22 MEDIUM 6.5 CVE-2020-20468 White Shark System (WSS) 1.3.2 is vulnerable to CSRF. Attackers can use the user_edit_password.php file to modify the user password. White Shark Systems No fix yet Fix from $1,6002021-06-21 HIGH 8.8 CVE-2021-32424 In TrendNet TW100-S4W1CA 2.3.32, due to a lack of proper session controls, a threat actor could make unauthorized changes to an affected router via a… Tw100 S4w1ca Firmware Mitigation only Fix from $1,9502021-06-17 MEDIUM 6.5 CVE-2020-35759 bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely). Bloofoxcms No fix yet Fix from $1,6002021-06-16 MEDIUM 6.1 CVE-2021-24349 This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sani… Gallery From Files after 1.6.0 Fix from $1,6002021-06-14 HIGH 8.8 CVE-2020-13663 Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead… Drupal 7.72 / 8.8.8+ Fix from $1,9502021-06-11 HIGH 8.8 CVE-2021-31659 TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information i… Tl Sg2005 Firmware Mitigation only Fix from $1,9502021-06-10 HIGH 8.8 CVE-2021-21665 A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker… Xebialabs Xl Deploy after 10.0.1 Fix from $1,9502021-06-10 HIGH 8.1 CVE-2021-32677 FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cooki… Fedora 0.65.2+ Fix from $1,9502021-06-09 HIGH 8.8 CVE-2021-29995 A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in … Cloverdx 5.7.1 / 5.8.2+ Fix from $1,9502021-06-09 HIGH 8.8 CVE-2021-26474 Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in thi… Bdr Suite 4.2.0+ Fix from $1,9502021-06-08 HIGH 8.8 CVE-2020-26516 A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF t… Codebeamer No fix yet Fix from $1,9502021-06-08 HIGH 8.8 CVE-2020-18264 Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-L… Simple Log No fix yet Fix from $1,9502021-06-07