Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-37758 Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attackers to escalate privileges. Mitigation only Fix from $1,9502024-12-20 MEDIUM 6.1 CVE-2024-11812 The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.091. This is d… Mitigation only Fix from $1,6002024-12-20 MEDIUM 5.5 CVE-2024-44293 A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. A user may be able to … macOS Mitigation only Fix from $1,6002024-12-20 HIGH 8.8 CVE-2024-56116 A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account. Amiro.cms 7.8.4+ Fix from $1,9502024-12-18 MEDIUM 6.5 CVE-2024-56140 Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware allows requests to bypass CSRF… Astro 4.16.17+ Fix from $1,6002024-12-18 HIGH 8.8 CVE-2024-55088 GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module. Getsimple Cms Mitigation only Fix from $1,9502024-12-18 MEDIUM 6.1 CVE-2024-12454 The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… Mitigation only Fix from $1,6002024-12-18 MEDIUM 5.4 CVE-2024-12554 The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is du… Mitigation only Fix from $1,6002024-12-18 MEDIUM 5.4 CVE-2024-10892 The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged… Cost Calculator Builder 3.2.43+ Fix from $1,6002024-12-18 HIGH 8.8 CVE-2024-12293 The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.64.3. This is due to mi… Mitigation only Fix from $1,9502024-12-17 MEDIUM 6.1 CVE-2024-12219 The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23. This is due t… Mitigation only Fix from $1,6002024-12-17 MEDIUM 6.1 CVE-2024-12220 The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to … Mitigation only Fix from $1,6002024-12-17 HIGH 7.1 CVE-2024-56017 Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects Stop Registration Spam: from… Mitigation only Fix from $1,9502024-12-16 HIGH 8.0 CVE-2024-37774 A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administ… Dctrack Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-56015 Cross-Site Request Forgery (CSRF) vulnerability in John Godley Tidy Up allows Reflected XSS.This issue affects Tidy Up: from n/a through 1.3. Mitigation only Fix from $1,9502024-12-16 MEDIUM 6.5 CVE-2024-56005 Cross-Site Request Forgery (CSRF) vulnerability in Posti Posti Shipping posti-shipping allows Cross Site Request Forgery.This issue affects Posti Shi… Mitigation only Fix from $1,6002024-12-16 CRITICAL 9.8 CVE-2024-56012 Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Flash News / Post (Responsive) flashnews-fading-effect-pearlbells allows Privilege Escalat… Mitigation only Fix from $2,3002024-12-16 HIGH 7.1 CVE-2024-54433 Cross-Site Request Forgery (CSRF) vulnerability in Marcel CL Simple Booking Widget simple-booking-widget allows Stored XSS.This issue affects Simple … Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54434 Cross-Site Request Forgery (CSRF) vulnerability in BenJemin phZoom phzoom allows Stored XSS.This issue affects phZoom: from n/a through <= 1.2.92. Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54435 Cross-Site Request Forgery (CSRF) vulnerability in Thomas Hoefter Onlywire Multi Autosubmitter onlywire-multi-autosubmitter allows Stored XSS.This is… Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54436 Cross-Site Request Forgery (CSRF) vulnerability in milordk Jet Footer Code jet-footer-code allows Stored XSS.This issue affects Jet Footer Code: from… Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54438 Cross-Site Request Forgery (CSRF) vulnerability in gaxx Gaxx Keywords gaxx-keywords allows Stored XSS.This issue affects Gaxx Keywords: from n/a thro… Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54439 Cross-Site Request Forgery (CSRF) vulnerability in Alok Tiwari Amazon Product Price amazon-product-price allows Stored XSS.This issue affects Amazon … Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54440 Cross-Site Request Forgery (CSRF) vulnerability in blueskyy WP-Ban-User wp-ban-user allows Stored XSS.This issue affects WP-Ban-User: from n/a throug… Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54426 Cross-Site Request Forgery (CSRF) vulnerability in crossfitatgg LeaderBoard Plugin leaderboard-lite allows Stored XSS.This issue affects LeaderBoard … Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54427 Cross-Site Request Forgery (CSRF) vulnerability in ljmacphee Category of Posts list-one-category-of-posts allows Stored XSS.This issue affects Catego… Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54428 Cross-Site Request Forgery (CSRF) vulnerability in onigetoc Add image to Post add-image-to-post allows Stored XSS.This issue affects Add image to Pos… Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54429 Cross-Site Request Forgery (CSRF) vulnerability in ivan-ovsyannikov Aphorismus aphorismus allows Stored XSS.This issue affects Aphorismus: from n/a t… Mitigation only Fix from $1,9502024-12-16 MEDIUM 5.4 CVE-2024-54430 Cross-Site Request Forgery (CSRF) vulnerability in Europe Ecologie Les Verts EELV Newsletter eelv-newsletter allows Cross Site Request Forgery.This i… Mitigation only Fix from $1,6002024-12-16 HIGH 7.1 CVE-2024-54431 Cross-Site Request Forgery (CSRF) vulnerability in phpdevp Admin Customization wpp-customization allows Stored XSS.This issue affects Admin Customiza… Mitigation only Fix from $1,9502024-12-16