Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2024-54386 Cross-Site Request Forgery (CSRF) vulnerability in pushmonkey Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart push-monkey-des… Mitigation only Fix from $1,9502024-12-16 CRITICAL 9.6 CVE-2024-54368 Cross-Site Request Forgery (CSRF) vulnerability in rubengarzajr GitSync git-sync allows Code Injection.This issue affects GitSync: from n/a through <… Mitigation only Fix from $2,3002024-12-16 CRITICAL 9.6 CVE-2024-54372 Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Insertify insertify allows Code Injection.This issue affects Insertify: from n/a throu… Mitigation only Fix from $2,3002024-12-16 HIGH 8.8 CVE-2024-54355 Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.This issue affects WP Mailster… Wp Mailster 1.8.17+ Fix from $1,9502024-12-16 MEDIUM 5.4 CVE-2024-54356 Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allow… Online Booking \& Scheduling Calendar 4.5.2+ Fix from $1,6002024-12-16 HIGH 7.1 CVE-2024-54331 Cross-Site Request Forgery (CSRF) vulnerability in Micha I Plant A Tree i-plant-a-tree allows Stored XSS.This issue affects I Plant A Tree: from n/a … Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54332 Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allows Stored XSS.This issue affec… Mitigation only Fix from $1,9502024-12-16 HIGH 8.8 CVE-2024-54352 Cross-Site Request Forgery (CSRF) vulnerability in Sabri Sogrid sogrid allows Privilege Escalation.This issue affects Sogrid: from n/a through <= 1.5… Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-54353 Cross-Site Request Forgery (CSRF) vulnerability in wpgear Hack-Info hack-info allows Stored XSS.This issue affects Hack-Info: from n/a through <= 3.1… Mitigation only Fix from $1,9502024-12-16 HIGH 8.1 CVE-2024-12642 TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides API… Tenderdoctransfer 0.41.157+ Fix from $1,9502024-12-16 HIGH 8.1 CVE-2024-12643 The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs … Mitigation only Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-12644 The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for com… Mitigation only Fix from $1,9502024-12-16 MEDIUM 6.5 CVE-2024-12645 The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local web server and provides APIs f… Mitigation only Fix from $1,6002024-12-16 HIGH 8.1 CVE-2024-12646 The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs… Mitigation only Fix from $1,9502024-12-16 MEDIUM 6.1 CVE-2024-12555 The SIP Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing… Mitigation only Fix from $1,6002024-12-14 CRITICAL 9.6 CVE-2024-54139 Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scrip… Itop 2.7.11 / 3.1.2+ Fix from $2,3002024-12-13 HIGH 7.1 CVE-2024-54351 Cross-Site Request Forgery (CSRF) vulnerability in Thomas K Landis Fancy Roller Scroller fancy-roller-scroller allows Stored XSS.This issue affects F… Mitigation only Fix from $1,9502024-12-13 HIGH 7.1 CVE-2024-54337 Cross-Site Request Forgery (CSRF) vulnerability in DevriX DX Dark Site devrix-dark-site allows Stored XSS.This issue affects DX Dark Site: from n/a t… Mitigation only Fix from $1,9502024-12-13 HIGH 8.8 CVE-2024-54248 Cross-Site Request Forgery (CSRF) vulnerability in eewee eewee admin custom eewee-admincustom allows Privilege Escalation.This issue affects eewee ad… Mitigation only Fix from $1,9502024-12-13 MEDIUM 6.5 CVE-2023-41686 Cross-Site Request Forgery (CSRF) vulnerability in ilGhera Woocommerce Support System allows Cross Site Request Forgery.This issue affects Woocommerc… Mitigation only Fix from $1,6002024-12-13 MEDIUM 6.1 CVE-2024-12572 The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due … Mitigation only Fix from $1,6002024-12-13 HIGH 8.8 CVE-2024-11689 The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.29. This is due to … Mitigation only Fix from $1,9502024-12-12 MEDIUM 6.1 CVE-2024-11417 The dejure.org Vernetzungsfunktion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.97.5. Thi… Mitigation only Fix from $1,6002024-12-12 MEDIUM 6.1 CVE-2024-11419 The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missin… Mitigation only Fix from $1,6002024-12-12 MEDIUM 6.3 CVE-2024-28141 The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on th… Mitigation only Fix from $1,6002024-12-11 MEDIUM 6.1 CVE-2024-12004 The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. Thi… Mitigation only Fix from $1,6002024-12-11 HIGH 8.8 CVE-2024-55500 Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution o… Patch available Fix from $1,9502024-12-10 HIGH 8.8 CVE-2020-28398 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX … Mitigation only Fix from $1,9502024-12-10 HIGH 7.1 CVE-2024-54226 Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This issue affects Country Blocker… Mitigation only Fix from $1,9502024-12-09 MEDIUM 5.4 CVE-2023-28688 Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk TH Variation Swatches allows Cross Site Request Forgery.This issue affects TH Variation … Variation Swatches 1.2.8+ Fix from $1,6002024-12-09