Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2025-24713 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder button-generation allows Cross Site Request F… Mitigation only Fix from $1,6002025-01-24 MEDIUM 5.4 CVE-2025-24714 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu bubble-menu allows Cross Site Request Forgery.This … Mitigation only Fix from $1,6002025-01-24 MEDIUM 5.4 CVE-2025-24715 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Counter Box counter-box allows Cross Site Request Forgery.This issue affects Counter B… Counter Box 2.0.6+ Fix from $1,6002025-01-24 MEDIUM 5.4 CVE-2025-24647 Cross-Site Request Forgery (CSRF) vulnerability in datafeedr WooCommerce Cloak Affiliate Links woocommerce-cloak-affiliate-links allows Cross Site Re… Mitigation only Fix from $1,6002025-01-24 HIGH 7.1 CVE-2025-24636 Cross-Site Request Forgery (CSRF) vulnerability in Rick Laymance MachForm Shortcode machform-shortcode allows Stored XSS.This issue affects MachForm … Mitigation only Fix from $1,9502025-01-24 MEDIUM 5.4 CVE-2025-24622 Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Job Board Manager job-board-manager allows Cross Site Request Forgery.This issue affec… Mitigation only Fix from $1,6002025-01-24 MEDIUM 6.5 CVE-2025-24572 Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Request Forgery.This issue affe… Mitigation only Fix from $1,6002025-01-24 HIGH 7.1 CVE-2025-24555 Cross-Site Request Forgery (CSRF) vulnerability in subscriptiondna Subscription DNA subscriptiondna allows Stored XSS.This issue affects Subscription… Mitigation only Fix from $1,9502025-01-24 HIGH 7.1 CVE-2025-24561 Cross-Site Request Forgery (CSRF) vulnerability in awcode ReviewsTap reviewstap allows Stored XSS.This issue affects ReviewsTap: from n/a through <= … Mitigation only Fix from $1,9502025-01-24 HIGH 7.1 CVE-2025-24562 Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access KBucket kbucket allows Stored XSS.This issue affects KBucket: from n/a through <= 4… Mitigation only Fix from $1,9502025-01-24 MEDIUM 5.4 CVE-2025-24546 Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.… Ultimate Coming Soon \& Maintenance 1.1.0+ Fix from $1,6002025-01-24 HIGH 7.1 CVE-2025-22768 Cross-Site Request Forgery (CSRF) vulnerability in JinHan Park Rocket Media Library Mime Type rocket-media-library-mime-type allows Stored XSS.This i… Mitigation only Fix from $1,9502025-01-23 HIGH 7.3 CVE-2024-56924 A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript… Internet Banking System No fix yet Fix from $1,9502025-01-22 HIGH 8.8 CVE-2025-24398 Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection… Bitbucket Server Integration 4.1.4+ Fix from $1,9502025-01-22 HIGH 7.1 CVE-2025-23803 Cross-Site Request Forgery (CSRF) vulnerability in Rik Schennink Snippy snippy allows Reflected XSS.This issue affects Snippy: from n/a through <= 1.… Mitigation only Fix from $1,9502025-01-22 HIGH 7.1 CVE-2025-23806 Cross-Site Request Forgery (CSRF) vulnerability in ThemeFarmer Ultimate Subscribe ultimate-subscribe allows Reflected XSS.This issue affects Ultimate… Mitigation only Fix from $1,9502025-01-22 MEDIUM 6.1 CVE-2025-21550 Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Web UI). Su… Financial Services Behavior Detection Platform Mitigation only Fix from $1,6002025-01-21 MEDIUM 6.1 CVE-2025-21538 Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected … Jd Edwards Enterpriseone Tools 9.2.9.2+ Fix from $1,6002025-01-21 MEDIUM 5.4 CVE-2025-21526 Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Su… Primavera P6 Enterprise Project Portfolio Management after 23.12.10.0 Fix from $1,6002025-01-21 MEDIUM 6.1 CVE-2025-21513 Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected … Jd Edwards Enterpriseone Tools 9.2.9.0+ Fix from $1,6002025-01-21 MEDIUM 5.4 CVE-2025-21507 Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected … Jd Edwards Enterpriseone Tools 9.2.9.0+ Fix from $1,6002025-01-21 MEDIUM 6.1 CVE-2025-21489 Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping). Supported versions that are … E Business Suite after 12.2.10 Fix from $1,6002025-01-21 MEDIUM 6.1 CVE-2024-54792 A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead a… Spagobi No fix yet Fix from $1,6002025-01-21 HIGH 8.2 CVE-2024-53829 CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Cross-site request forgery al… Codechecker 6.24.5+ Fix from $1,9502025-01-21 HIGH 7.1 CVE-2025-24001 Cross-Site Request Forgery (CSRF) vulnerability in Ngô Thắng IT PPO Call To Actions ppo-call-to-actions allows Cross Site Request Forgery.This issue … Mitigation only Fix from $1,9502025-01-21 MEDIUM 6.1 CVE-2024-13444 The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2. This is due to missing or in… Mitigation only Fix from $1,6002025-01-21 MEDIUM 6.1 CVE-2024-12005 The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or… Wp Bibtex 3.0.2+ Fix from $1,6002025-01-21 HIGH 8.1 CVE-2025-23044 PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behal… Pwndoc 0.9.0+ Fix from $1,9502025-01-20 MEDIUM 6.1 CVE-2024-13432 The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missin… Mitigation only Fix from $1,6002025-01-18 MEDIUM 6.1 CVE-2024-12385 The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing… Wp Abstracts 2.7.3+ Fix from $1,6002025-01-18