Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2020-37054 Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML pa… Navigate Cms No fix yet Fix from $1,9502026-01-30 MEDIUM 5.3 CVE-2020-37046 Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized admin … No fix yet Fix from $1,6002026-01-30 MEDIUM 5.3 CVE-2020-37026 Sickbeard alpha contains a cross-site request forgery vulnerability that allows attackers to disable authentication by submitting crafted configurati… No fix yet Fix from $1,6002026-01-30 MEDIUM 5.3 CVE-2025-15550 birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows attackers to exploit GET-based q… Mitigation only Fix from $1,6002026-01-29 HIGH 8.1 CVE-2025-14472 Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub:… Acquia Content Hub 3.6.4 / 3.7.3+ Fix from $1,9502026-01-28 HIGH 8.1 CVE-2025-13982 Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This issue affects Login Time Rest… Login Time Restriction 1.0.3+ Fix from $1,9502026-01-28 HIGH 8.5 CVE-2025-59901 Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient val… Mitigation only Fix from $1,9502026-01-28 HIGH 8.0 CVE-2025-59891 Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user c… Diskpulse Mitigation only Fix from $1,9502026-01-28 HIGH 8.0 CVE-2025-59892 Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user c… Diskpulse Mitigation only Fix from $1,9502026-01-28 HIGH 8.0 CVE-2025-59893 Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user c… Diskpulse Mitigation only Fix from $1,9502026-01-28 HIGH 8.0 CVE-2025-59894 Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user c… Diskpulse Mitigation only Fix from $1,9502026-01-28 HIGH 8.8 CVE-2026-24345 Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to t… Ezcast Pro Dongle Ii Firmware Mitigation only Fix from $1,9502026-01-27 MEDIUM 5.0 CVE-2026-24408 sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication f… Sigstore Python 4.2.0+ Fix from $1,6002026-01-26 MEDIUM 5.4 CVE-2026-24384 Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-24374 Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Cross … Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-24365 Cross-Site Request Forgery (CSRF) vulnerability in storeapps Stock Manager for WooCommerce woocommerce-stock-manager allows Cross Site Request Forger… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-22483 Cross-Site Request Forgery (CSRF) vulnerability in winkm89 teachPress teachpress allows Cross Site Request Forgery.This issue affects teachPress: fro… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-22382 Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Cross Site Re… Mitigation only Fix from $1,6002026-01-22 HIGH 7.1 CVE-2026-22355 Cross-Site Request Forgery (CSRF) vulnerability in gregmolnar Simple XML Sitemap simple-xml-sitemap allows Stored XSS.This issue affects Simple XML S… Mitigation only Fix from $1,9502026-01-22 MEDIUM 6.5 CVE-2025-70899 PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform un… Online Course Registration No fix yet Fix from $1,6002026-01-22 MEDIUM 6.5 CVE-2021-47830 GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, … Getsimplecms No fix yet Fix from $1,6002026-01-21 MEDIUM 5.9 CVE-2026-23950 node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicod… Tar 7.5.4+ Fix from $1,6002026-01-20 HIGH 8.8 CVE-2026-1169 A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. Such manipulation leads to cr… Prime after 0.4.0 Fix from $1,9502026-01-19 MEDIUM 6.5 CVE-2026-1148 A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This vulnerability affects unknown … Patients Waiting Area Queue Management System Mitigation only Fix from $1,6002026-01-19 MEDIUM 6.5 CVE-2026-1142 A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in … News Portal No fix yet Fix from $1,6002026-01-19 MEDIUM 5.3 CVE-2021-47820 Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can… No fix yet Fix from $1,6002026-01-16 MEDIUM 5.3 CVE-2021-47800 b2evolution 7.2.2 contains a cross-site request forgery vulnerability that allows attackers to modify admin account details without authentication. A… No fix yet Fix from $1,6002026-01-16 HIGH 8.8 CVE-2026-23622 Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF fo… Easy\!appointments after 1.5.2 Fix from $1,9502026-01-15 MEDIUM 6.5 CVE-2021-47754 Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. At… Arunna No fix yet Fix from $1,6002026-01-15 HIGH 7.1 CVE-2025-14615 The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… Mitigation only Fix from $1,9502026-01-14