Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2025-65840 PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController. Publiccms No fix yet Fix from $1,9502025-12-01 HIGH 8.8 CVE-2024-53684 A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTT… Diris M 70 Firmware Mitigation only Fix from $1,9502025-12-01 MEDIUM 5.4 CVE-2025-13296 Cross-Site Request Forgery (CSRF) vulnerability in Tekrom Technology Inc. T-Soft E-Commerce allows Cross Site Request Forgery. This issue affects T-… Mitigation only Fix from $1,6002025-12-01 HIGH 8.8 CVE-2025-13790 A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The… Scada Lts after 2.7.8.1 Fix from $1,9502025-11-30 MEDIUM 6.8 CVE-2025-53897 Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain ac… Kiteworks Managed File Transfer 9.1.0+ Fix from $1,6002025-11-29 MEDIUM 5.5 CVE-2025-51733 Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0. Unica No fix yet Fix from $1,6002025-11-28 HIGH 8.8 CVE-2025-62593 KEV Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerabi… Ray 2.52.0+ Fix from $1,9502025-11-26 HIGH 8.6 CVE-2025-12061 The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users… Mitigation only Fix from $1,9502025-11-26 CRITICAL 9.6 CVE-2025-60739 Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 … Eve X1 Server Firmware No fix yet Fix from $2,3002025-11-25 MEDIUM 6.5 CVE-2025-62497 Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a specially crafted webpage while logge… Snc Cx600w Firmware 2.8.0+ Fix from $1,6002025-11-25 HIGH 8.8 CVE-2025-56400 Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Sma… Smartlife 6.5.0+ Fix from $1,9502025-11-24 MEDIUM 5.7 CVE-2025-63952 A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create a… Pro Convert Hdmi 4k Plus Firmware No fix yet Fix from $1,6002025-11-24 MEDIUM 6.5 CVE-2025-63953 A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create a… Ultra Encode Hdmi Firmware No fix yet Fix from $1,6002025-11-24 MEDIUM 6.5 CVE-2025-65107 Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in… Langfuse 2.95.12 / 3.131.0+ Fix from $1,6002025-11-21 HIGH 8.8 CVE-2025-11087 The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.0.1. Thi… Mitigation only Fix from $1,9502025-11-21 MEDIUM 6.1 CVE-2025-13134 The AuthorSure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or … Mitigation only Fix from $1,6002025-11-21 MEDIUM 6.5 CVE-2025-62687 Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be perf… Logstare Collector 2.4.2+ Fix from $1,6002025-11-21 MEDIUM 6.8 CVE-2025-62346 A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwan… No fix yet Fix from $1,6002025-11-20 MEDIUM 5.3 CVE-2025-12535 The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to th… Mitigation only Fix from $1,6002025-11-19 HIGH 7.5 CVE-2025-63955 A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to… Student Record System No fix yet Fix from $1,9502025-11-18 MEDIUM 6.5 CVE-2025-59112 Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft special website, which when visited… Windu Cms Mitigation only Fix from $1,6002025-11-18 MEDIUM 6.5 CVE-2025-59114 Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft special website, which when visit… Windu Cms Mitigation only Fix from $1,6002025-11-18 MEDIUM 6.5 CVE-2025-59110 Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechanism can be bypassed by using C… Windu Cms Mitigation only Fix from $1,6002025-11-18 HIGH 8.8 CVE-2025-6670 A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operation… Api Control Plane Mitigation only Fix from $1,9502025-11-18 MEDIUM 6.1 CVE-2025-12404 The Like-it plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or inc… Mitigation only Fix from $1,6002025-11-18 MEDIUM 6.1 CVE-2025-12406 The Project Honey Pot Spam Trap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is… Mitigation only Fix from $1,6002025-11-18 HIGH 8.8 CVE-2025-55057 Multiple CWE-352 Cross-Site Request Forgery (CSRF) Rumpus No fix yet Fix from $1,9502025-11-17 HIGH 8.1 CVE-2025-13282 TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and prov… Tenderdoctransfer 0.41.159+ Fix from $1,9502025-11-17 HIGH 7.1 CVE-2025-13283 TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server… Tenderdoctransfer 0.41.159+ Fix from $1,9502025-11-17 MEDIUM 6.5 CVE-2025-13179 A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects so… Wholesale after 2025-10-16 Fix from $1,6002025-11-14