Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2025-23455 Cross-Site Request Forgery (CSRF) vulnerability in Master Software Solutions WP VTiger Synchronization msstiger allows Stored XSS.This issue affects … Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23456 Cross-Site Request Forgery (CSRF) vulnerability in Oddthinking EmailShroud emailshroud allows Reflected XSS.This issue affects EmailShroud: from n/a … Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23463 Cross-Site Request Forgery (CSRF) vulnerability in Mukesh Dak MD Custom content after or before of post md-custom-content allows Stored XSS.This issu… Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23467 Cross-Site Request Forgery (CSRF) vulnerability in vimal.ghorecha RSS News Scroller rss-news-scroller allows Stored XSS.This issue affects RSS News S… Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23470 Cross-Site Request Forgery (CSRF) vulnerability in xavsio4 Visit Site Link enhanced visit-site-link-enhanced allows Stored XSS.This issue affects Vis… Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23471 Cross-Site Request Forgery (CSRF) vulnerability in etemplates ECT Add to Cart Button ect-add-to-cart-button allows Stored XSS.This issue affects ECT … Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23476 Cross-Site Request Forgery (CSRF) vulnerability in isnowfy my-related-posts my-related-posts allows Stored XSS.This issue affects my-related-posts: f… Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23442 Cross-Site Request Forgery (CSRF) vulnerability in mschertel Shockingly Big IE6 Warning shockingly-big-ie6-warning allows Stored XSS.This issue affec… Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23445 Cross-Site Request Forgery (CSRF) vulnerability in scottswezey Easy Tynt easy-tynt allows Cross Site Request Forgery.This issue affects Easy Tynt: fr… Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23430 Cross-Site Request Forgery (CSRF) vulnerability in Oren Yomtov Mass Custom Fields Manager mass-custom-fields-manager allows Reflected XSS.This issue … Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23435 Cross-Site Request Forgery (CSRF) vulnerability in marcucci Password Protect Plugin for WordPress password-protect-plugin-for-wordpress allows Stored… Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23436 Cross-Site Request Forgery (CSRF) vulnerability in capa Wp-Scribd-List wp-scribd-list allows Stored XSS.This issue affects Wp-Scribd-List: from n/a t… Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23424 Cross-Site Request Forgery (CSRF) vulnerability in bnovotny Marquee Style RSS News Ticker marquee-style-rss-news-ticker allows Cross Site Request For… Mitigation only Fix from $1,9502025-01-16 HIGH 7.1 CVE-2025-23426 Cross-Site Request Forgery (CSRF) vulnerability in Binesh Dobhal go Social go-social allows Stored XSS.This issue affects go Social: from n/a through… Mitigation only Fix from $1,9502025-01-16 HIGH 8.6 CVE-2025-22784 Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Background Control background-control allows Path Traversal.This issue affects Backgro… Mitigation only Fix from $1,9502025-01-15 HIGH 8.8 CVE-2024-50858 Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by… Gestioip No fix yet Fix from $1,9502025-01-14 MEDIUM 5.4 CVE-2024-55922 TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi… TYPO3 10.4.48 / 11.5.42+ Fix from $1,6002025-01-14 HIGH 8.0 CVE-2024-55924 TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi… TYPO3 11.5.42+ Fix from $1,9502025-01-14 MEDIUM 6.5 CVE-2024-55945 TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi… TYPO3 11.5.42+ Fix from $1,6002025-01-14 MEDIUM 5.4 CVE-2024-55894 TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi… TYPO3 10.4.48 / 11.5.42+ Fix from $1,6002025-01-14 HIGH 8.8 CVE-2024-55921 TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi… TYPO3 10.4.48 / 11.5.42+ Fix from $1,9502025-01-14 MEDIUM 6.5 CVE-2025-21193 Active Directory Federation Server Spoofing Vulnerability Windows Server 2016 10.0.14393.7699 / 10.0.17763.6775+ Fix from $1,6002025-01-14 MEDIUM 6.1 CVE-2025-23081 Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikim… Mitigation only Fix from $1,6002025-01-14 HIGH 7.1 CVE-2024-47100 A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0X… Mitigation only Fix from $1,9502025-01-14 MEDIUM 6.1 CVE-2025-0393 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1… Royal Elementor Addons after 1.7.1006 Fix from $1,6002025-01-14 MEDIUM 5.4 CVE-2023-42234 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function. Helpdeskadvanced after 11.0.33 Fix from $1,6002025-01-13 HIGH 7.5 CVE-2025-22963 Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin. Teedy after 1.11 Fix from $1,9502025-01-13 HIGH 8.8 CVE-2025-23113 An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file… Redcap Mitigation only Fix from $1,9502025-01-10 HIGH 8.7 CVE-2024-6662 Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under "/edytor/index.php… Mitigation only Fix from $1,9502025-01-10 HIGH 8.8 CVE-2024-13284 Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before… Gutenberg 2.13.0 / 3.0.5+ Fix from $1,9502025-01-09