Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.4 CVE-2024-51382 Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw… Jatos No fix yet Fix from $1,9502024-11-05 HIGH 8.8 CVE-2024-10711 The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to m… Woocommerce Report 1.5.2+ Fix from $1,9502024-11-05 HIGH 8.8 CVE-2024-31998 Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versio… Itop 3.1.2+ Fix from $1,9502024-11-05 MEDIUM 6.1 CVE-2024-48057 localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a … Localai after 2.20.1 Fix from $1,6002024-11-04 MEDIUM 5.4 CVE-2024-30617 A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a… Chamilo Lms Patch available Fix from $1,6002024-11-04 HIGH 8.8 CVE-2024-41744 IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tra… Cics Tx Mitigation only Fix from $1,9502024-11-01 CRITICAL 9.8 CVE-2024-47359 Cross-Site Request Forgery (CSRF) vulnerability in averta Depicter Slider depicter.This issue affects Depicter Slider: from n/a through <= 3.2.2. Depicter 3.5.0+ Fix from $2,3002024-11-01 MEDIUM 6.5 CVE-2024-10605 A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This affects an unknown part of t… Blood Bank Management System No fix yet Fix from $1,6002024-11-01 HIGH 8.8 CVE-2024-43984 Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publish… Podlove Podcast Publisher 4.1.14+ Fix from $1,9502024-10-31 CRITICAL 9.6 CVE-2024-49674 Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server… Mitigation only Fix from $2,3002024-10-31 HIGH 8.8 CVE-2024-49685 Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Fo… Custom Twitter Feeds 2.2.4+ Fix from $1,9502024-10-31 MEDIUM 6.1 CVE-2024-9434 The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is … Mitigation only Fix from $1,6002024-10-31 HIGH 8.8 CVE-2024-48311 Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function. Piwigo No fix yet Fix from $1,9502024-10-31 MEDIUM 6.5 CVE-2024-10557 A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an … Blood Bank Management System No fix yet Fix from $1,6002024-10-31 HIGH 8.8 CVE-2024-24777EPSS 8% A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted H… Wbr 6012 Firmware No fix yet Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-9990 The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This is due to missing nonce vali… Crypto Tool after 2.16 Fix from $1,9502024-10-29 HIGH 8.8 CVE-2024-50466 Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkmysite allows Cross Site Reque… Darkmysite after 1.2.8 Fix from $1,9502024-10-29 MEDIUM 6.5 CVE-2024-6673 A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-web… Lollms Web Ui 10+ Fix from $1,6002024-10-29 MEDIUM 6.1 CVE-2024-49672 Cross-Site Request Forgery (CSRF) vulnerability in giffordcheung Google Docs RSVP google-docs-rsvp-guestlist allows Stored XSS.This issue affects Goo… Google Docs Rsvp after 2.0.1 Fix from $1,6002024-10-29 MEDIUM 6.3 CVE-2024-48291 dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17 Dingfanzu Cms No fix yet Fix from $1,6002024-10-28 MEDIUM 6.5 CVE-2024-10448 A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is som… Blood Bank Management System No fix yet Fix from $1,6002024-10-28 MEDIUM 6.3 CVE-2024-48191 dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17 Dingfanzu Cms No fix yet Fix from $1,6002024-10-28 HIGH 8.8 CVE-2022-30357 OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email p… Ovaledge after 5.2.8 Fix from $1,9502024-10-25 MEDIUM 5.3 CVE-2023-26248 The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information … Mitigation only Fix from $1,6002024-10-25 HIGH 8.8 CVE-2024-9598 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… Accelerated Mobile Pages 1.0.99.2+ Fix from $1,9502024-10-25 HIGH 8.8 CVE-2024-47879 OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `pre… Openrefine 3.8.3+ Fix from $1,9502024-10-24 MEDIUM 6.3 CVE-2024-9943 The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … Multivendorx 4.2.5+ Fix from $1,6002024-10-24 MEDIUM 6.1 CVE-2024-8980 The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through u… Digital Experience Platform 7.0.6 / 7.1.3+ Fix from $1,6002024-10-22 HIGH 8.8 CVE-2024-26271 Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 thro… Digital Experience Platform 7.4.3.112 / 2023.q3.6+ Fix from $1,9502024-10-22 HIGH 8.8 CVE-2024-26272 Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 throu… Digital Experience Platform 7.4.3.108 / 2023.q3.6+ Fix from $1,9502024-10-22