Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.1 CVE-2025-7667 The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to… Mitigation only Fix from $1,9502025-07-15 MEDIUM 5.2 CVE-2025-7379 A security bypass vulnerability allows exploitation via Reverse Tabnabbing, a type of phishing attack where attackers can manipulate the content of t… Mitigation only Fix from $1,6002025-07-09 HIGH 8.7 CVE-2025-53540 arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Several OTA update examples and… Patch available Fix from $1,9502025-07-07 MEDIUM 5.4 CVE-2025-7133 A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manip… Online Movie Ticket Booking System No fix yet Fix from $1,6002025-07-07 HIGH 8.8 CVE-2025-53483 ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF tokens, allowing attackers to tri… Mitigation only Fix from $1,9502025-07-04 MEDIUM 6.1 CVE-2025-6041 The yContributors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing … Mitigation only Fix from $1,6002025-07-04 HIGH 8.8 CVE-2025-52841 Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This issue affects Laundry: 2.3.0. Laundry No fix yet Fix from $1,9502025-07-02 HIGH 8.8 CVE-2025-6459 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … Ads Pro after 4.89 Fix from $1,9502025-07-02 MEDIUM 5.1 CVE-2025-34050 A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malici… No fix yet Fix from $1,6002025-07-01 HIGH 8.8 CVE-2025-53095 Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site … Sunshine 2025.628.4510+ Fix from $1,9502025-07-01 HIGH 7.5 CVE-2025-24289 A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could a… Mitigation only Fix from $1,9502025-06-29 MEDIUM 6.5 CVE-2025-50369 A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Ge… Medical Card Generation System Mitigation only Fix from $1,6002025-06-27 MEDIUM 6.5 CVE-2025-50370 A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Ca… Medical Card Generation System Mitigation only Fix from $1,6002025-06-27 HIGH 7.1 CVE-2025-53332 Cross-Site Request Forgery (CSRF) vulnerability in ethoseo Track Everything track-everything allows Stored XSS.This issue affects Track Everything: f… Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53338 Cross-Site Request Forgery (CSRF) vulnerability in dor re.place replace allows Stored XSS.This issue affects re.place: from n/a through <= 0.2.1. Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53329 Cross-Site Request Forgery (CSRF) vulnerability in szajenw Społecznościowa 6 PL 2013 spolecznosciowa-6-pl-2013 allows Stored XSS.This issue affects S… Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53331 Cross-Site Request Forgery (CSRF) vulnerability in samcharrington RSS Digest rss-digest allows Stored XSS.This issue affects RSS Digest: from n/a thr… Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53315 Cross-Site Request Forgery (CSRF) vulnerability in alanft Relocate Upload relocate-upload allows Stored XSS.This issue affects Relocate Upload: from … Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53317 Cross-Site Request Forgery (CSRF) vulnerability in AcmeeDesign WPShapere - WordPress admin theme wpshapere-lite allows Stored XSS.This issue affects … Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53310 Cross-Site Request Forgery (CSRF) vulnerability in Funnnny HidePost hidepost allows Reflected XSS.This issue affects HidePost: from n/a through <= 2.… Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53311 Cross-Site Request Forgery (CSRF) vulnerability in Amol Nirmala Waman Navayan Subscribe navayan-subscribe allows Stored XSS.This issue affects Navaya… Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53312 Cross-Site Request Forgery (CSRF) vulnerability in Looks Awesome OnionBuzz onionbuzz-viral-quiz allows Stored XSS.This issue affects OnionBuzz: from … Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53313 Cross-Site Request Forgery (CSRF) vulnerability in plumwd Twitch TV Embed Suite twitch-tv-embed-suite allows Stored XSS.This issue affects Twitch TV … Mitigation only Fix from $1,9502025-06-27 CRITICAL 9.6 CVE-2025-53314 Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affects WP Optimizer: from n/a th… Mitigation only Fix from $2,3002025-06-27 HIGH 7.1 CVE-2025-53305 Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server forum-server allows Stored XSS.This issue affects WP Forum Server: fro… Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53308 Cross-Site Request Forgery (CSRF) vulnerability in gopi_plus Image Slider With Description image-slider-with-description allows Stored XSS.This issue… Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53274 Cross-Site Request Forgery (CSRF) vulnerability in Hossin Asaadi WP Permalink Translator wp-permalink-translator allows Stored XSS.This issue affects… Mitigation only Fix from $1,9502025-06-27 HIGH 8.8 CVE-2025-53277 Cross-Site Request Forgery (CSRF) vulnerability in Infigo Software IS-theme-companion weblizar-companion allows Object Injection.This issue affects I… Mitigation only Fix from $1,9502025-06-27 HIGH 7.1 CVE-2025-53271 Cross-Site Request Forgery (CSRF) vulnerability in Anton Bond Additional Order Filters for WooCommerce additional-order-filters-for-woocommerce allow… Mitigation only Fix from $1,9502025-06-27 MEDIUM 5.4 CVE-2025-53262 Cross-Site Request Forgery (CSRF) vulnerability in Writesonic Writesonic writesonic allows Cross Site Request Forgery.This issue affects Writesonic: … No fix yet Fix from $1,6002025-06-27