Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-45693 Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of t… Cloudstack 4.18.2.4 / 4.19.1.2+ Fix from $1,9502024-10-16 HIGH 8.8 CVE-2024-8507 The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to mis… File Manager 8.3.10+ Fix from $1,9502024-10-16 HIGH 8.3 CVE-2020-36839 The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.99. This is due to missing or… Mitigation only Fix from $1,9502024-10-16 HIGH 8.0 CVE-2020-36836 The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a la… Wp Fastest Cache 0.9.0.3+ Fix from $1,9502024-10-16 HIGH 8.8 CVE-2024-49340 IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions… Watson Studio Local Mitigation only Fix from $1,9502024-10-16 MEDIUM 6.1 CVE-2024-21202 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are af… Peoplesoft Enterprise Peopletools Mitigation only Fix from $1,6002024-10-15 HIGH 7.5 CVE-2024-41344 A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges. Codeigniter No fix yet Fix from $1,9502024-10-15 MEDIUM 5.9 CVE-2024-48913 Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Ty… Hono 4.6.5+ Fix from $1,6002024-10-15 MEDIUM 5.5 CVE-2024-48278 Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php. User Registration \& Login And User Management System No fix yet Fix from $1,6002024-10-15 HIGH 7.1 CVE-2024-6959 A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends… Lollms Web Ui No fix yet Fix from $1,9502024-10-13 MEDIUM 6.1 CVE-2024-9592 The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is du… Mitigation only Fix from $1,6002024-10-12 MEDIUM 6.5 CVE-2024-47828 ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smart… Ampache after 6.6.0 Fix from $1,6002024-10-09 HIGH 7.1 CVE-2024-44028 Cross-Site Request Forgery (CSRF) vulnerability in nicejob NiceJob nicejob allows Stored XSS.This issue affects NiceJob: from n/a through < 3.6.5. Mitigation only Fix from $1,9502024-10-06 MEDIUM 5.4 CVE-2024-47635 Cross-Site Request Forgery (CSRF) vulnerability in TinyPNG TinyPNG tiny-compress-images allows Cross Site Request Forgery.This issue affects TinyPNG:… Mitigation only Fix from $1,6002024-10-05 HIGH 8.8 CVE-2024-47846 Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Me… Cargo Patch available Fix from $1,9502024-10-05 HIGH 8.8 CVE-2024-43684 Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This iss… Timeprovider 4100 Firmware 2.4.7+ Fix from $1,9502024-10-04 HIGH 8.6 CVE-2024-41987 The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any valid… Mitigation only Fix from $1,9502024-10-03 MEDIUM 6.8 CVE-2023-7273 Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it i… Mitigation only Fix from $1,6002024-10-01 HIGH 8.8 CVE-2024-8458 Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remot… Gs 4210 24p2s Firmware 2.305b240719 / 3.305b240802+ Fix from $1,9502024-09-30 HIGH 8.8 CVE-2024-28948 Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, w… Adam 5630 Firmware 2.5.2+ Fix from $1,9502024-09-27 MEDIUM 6.5 CVE-2024-45987 Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker… Online Voting System No fix yet Fix from $1,6002024-09-26 MEDIUM 6.3 CVE-2024-45983 A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attack… Hospital Management System No fix yet Fix from $1,6002024-09-26 MEDIUM 6.5 CVE-2024-45372 MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the we… Mzk Dp300n Firmware after 1.04 Fix from $1,6002024-09-26 HIGH 8.0 CVE-2024-47082 Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as defined in the GraphQL multipar… Strawberry 0.243.0+ Fix from $1,9502024-09-25 HIGH 8.8 CVE-2024-47305 Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font use-any-font allows Cross Site Request Forgery.This issue affects Use Any… Use Any Font 6.3.09+ Fix from $1,9502024-09-25 HIGH 8.8 CVE-2024-47315 Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.15.1. Givewp 3.16.0+ Fix from $1,9502024-09-25 HIGH 8.8 CVE-2024-20437 A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-sit… Ios Xe Mitigation only Fix from $1,9502024-09-25 MEDIUM 6.5 CVE-2024-20414 A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cr… Ios Xe Mitigation only Fix from $1,6002024-09-25 MEDIUM 6.3 CVE-2024-46485 dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate Dingfanzu Cms No fix yet Fix from $1,6002024-09-25 HIGH 8.8 CVE-2024-8795 The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to … Ba Book Everything 1.6.21+ Fix from $1,9502024-09-24