Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2024-51636 Cross-Site Request Forgery (CSRF) vulnerability in Z.com byGMO GMO Social Connection gmo-social-connection allows Cross-Site Scripting (XSS).This iss… Mitigation only Fix from $1,9502024-11-19 HIGH 7.1 CVE-2024-51631 Cross-Site Request Forgery (CSRF) vulnerability in Md Eftakhairul Islam Sticky Social Bar sticky-social-bar allows Cross Site Request Forgery.This is… Mitigation only Fix from $1,9502024-11-19 HIGH 7.1 CVE-2024-51632 Cross-Site Request Forgery (CSRF) vulnerability in Sam Hoe SH Slideshow sh-slideshow allows Stored XSS.This issue affects SH Slideshow: from n/a thro… Mitigation only Fix from $1,9502024-11-19 HIGH 7.1 CVE-2024-50534 Cross-Site Request Forgery (CSRF) vulnerability in techdabang World Prayer Time world-prayer-time allows Stored XSS.This issue affects World Prayer T… No fix yet Fix from $1,9502024-11-19 HIGH 7.1 CVE-2024-50533 Cross-Site Request Forgery (CSRF) vulnerability in David Garcia Domain Sharding domain-sharding allows Stored XSS.This issue affects Domain Sharding:… Mitigation only Fix from $1,9502024-11-19 MEDIUM 6.1 CVE-2024-52424 Cross-Site Request Forgery (CSRF) vulnerability in sureshdsk wp-login customizer wp-login-customizer allows Stored XSS.This issue affects wp-login cu… Wp Login Customizer Mitigation only Fix from $1,6002024-11-18 HIGH 8.8 CVE-2024-48962 Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a… Ofbiz 18.12.17+ Fix from $1,9502024-11-18 HIGH 8.8 CVE-2024-52415 Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects S… Mitigation only Fix from $1,9502024-11-16 MEDIUM 5.3 CVE-2024-11118 The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to miss… Mitigation only Fix from $1,6002024-11-16 HIGH 7.4 CVE-2022-20853 A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to co… Telepresence Video Communication Server Mitigation only Fix from $1,9502024-11-15 MEDIUM 6.5 CVE-2023-0737 wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /… Wallabag Patch available Fix from $1,6002024-11-15 HIGH 7.1 CVE-2024-51658 Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.This issue affects WP Course Man… Mitigation only Fix from $1,9502024-11-14 HIGH 7.1 CVE-2024-51659 Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XSS.This issue affects Twitter … Mitigation only Fix from $1,9502024-11-14 MEDIUM 6.1 CVE-2024-51679 Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue affects Appointmind: from n/a th… Appointmind 4.1.0+ Fix from $1,6002024-11-14 HIGH 7.1 CVE-2024-51684 Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issue affects W3P SEO: from n/a t… Mitigation only Fix from $1,9502024-11-14 HIGH 7.1 CVE-2024-51687 Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This issue affects Platform.ly Offic… Mitigation only Fix from $1,9502024-11-14 HIGH 7.1 CVE-2024-51688 Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verification allows Stored XSS.This … Mitigation only Fix from $1,9502024-11-14 MEDIUM 6.5 CVE-2021-27704 Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page. Appspace Mitigation only Fix from $1,6002024-11-12 HIGH 8.1 CVE-2024-51484 Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR… Ampache No fix yet Fix from $1,9502024-11-11 HIGH 8.1 CVE-2024-51485 Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR… Ampache No fix yet Fix from $1,9502024-11-11 HIGH 8.1 CVE-2024-51487 Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR… Ampache No fix yet Fix from $1,9502024-11-11 MEDIUM 5.4 CVE-2024-51488 Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate C… Ampache No fix yet Fix from $1,6002024-11-11 MEDIUM 5.4 CVE-2024-51489 Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate C… Ampache No fix yet Fix from $1,6002024-11-11 HIGH 7.1 CVE-2024-51630 Cross-Site Request Forgery (CSRF) vulnerability in Lars Schenk Responsive Flickr Gallery responsive-flickr-gallery allows Stored XSS.This issue affec… Mitigation only Fix from $1,9502024-11-09 HIGH 7.1 CVE-2024-51647 Cross-Site Request Forgery (CSRF) vulnerability in Chaser324 Featured Posts Scroll allows Stored XSS.This issue affects Featured Posts Scroll: from n… Mitigation only Fix from $1,9502024-11-09 HIGH 8.8 CVE-2024-52002 Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerabilit… Itop 3.2.0+ Fix from $1,9502024-11-08 CRITICAL 9.3 CVE-2024-50966 dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin. Dingfanzu Cms No fix yet Fix from $2,3002024-11-08 HIGH 8.8 CVE-2019-20460 An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tokens or other mechanisms for v… Mitigation only Fix from $1,9502024-11-07 HIGH 8.0 CVE-2020-11919 An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection. Svakom Siime Eye Firmware No fix yet Fix from $1,9502024-11-07 HIGH 8.4 CVE-2024-51381 Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creat… Jatos No fix yet Fix from $1,9502024-11-05