Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-46394 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add Frogcms No fix yet Fix from $1,9502024-09-19 HIGH 8.8 CVE-2024-46086 FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123 Frogcms No fix yet Fix from $1,9502024-09-18 MEDIUM 6.1 CVE-2024-44064 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LikeBtn Like Button Rating likebtn-like-button.… Like Button Rating 2.6.54+ Fix from $1,6002024-09-17 HIGH 8.8 CVE-2024-46085 FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename Frogcms Mitigation only Fix from $1,9502024-09-17 HIGH 8.8 CVE-2024-46362 FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory Frogcms No fix yet Fix from $1,9502024-09-17 MEDIUM 6.5 CVE-2024-8490 The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missin… Propertyhive 2.0.20+ Fix from $1,6002024-09-17 MEDIUM 5.4 CVE-2024-8043 The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which… Vikinghammer Tweet after 0.2.4 Fix from $1,6002024-09-17 MEDIUM 6.5 CVE-2024-8044 The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to mak… Infolinks Ad Wrap after 1.0.2 Fix from $1,6002024-09-17 MEDIUM 6.5 CVE-2024-8047 The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to mak… Visual Sound after 1.06 Fix from $1,6002024-09-17 MEDIUM 5.4 CVE-2024-8051 The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which… Special Feed Items after 1.0.1 Fix from $1,6002024-09-17 MEDIUM 6.1 CVE-2024-8052 The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could… Review Ratings after 1.6 Fix from $1,6002024-09-17 MEDIUM 6.5 CVE-2024-8091 The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to m… Enhanced Search Box after 0.6.1 Fix from $1,6002024-09-17 MEDIUM 5.4 CVE-2024-8092 The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi… Accordion Image Menu after 3.1.3 Fix from $1,6002024-09-17 MEDIUM 6.5 CVE-2024-8093 The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a … Posts Reminder after 0.20 Fix from $1,6002024-09-17 HIGH 8.1 CVE-2024-6862 A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerabilit… Lunary Patch available Fix from $1,9502024-09-13 HIGH 8.8 CVE-2024-7423 The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or in… Stream 4.0.2+ Fix from $1,9502024-09-13 MEDIUM 6.8 CVE-2024-7863 The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow at… Favicon Generator 2.1+ Fix from $1,6002024-09-13 MEDIUM 6.5 CVE-2024-7864 The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing… Favicon Generator 2.1+ Fix from $1,6002024-09-13 MEDIUM 6.5 CVE-2024-7862 The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow … Blogintroduction Wordpress Plugin after 0.3.0 Fix from $1,6002024-09-12 MEDIUM 6.1 CVE-2024-7816 The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could all… Gixaw Chat after 1.0 Fix from $1,6002024-09-12 MEDIUM 6.5 CVE-2024-7817 The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users d… Misiek Photo Album after 1.4.3 Fix from $1,6002024-09-12 MEDIUM 6.5 CVE-2024-7820 The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a log… Ilc Thickbox after 1.0 Fix from $1,6002024-09-12 MEDIUM 6.5 CVE-2024-7859 The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a lo… Visual Sound after 1.03 Fix from $1,6002024-09-12 MEDIUM 6.1 CVE-2024-6017 The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whic… Music Request Manager after 1.3 Fix from $1,6002024-09-12 CRITICAL 9.8 CVE-2024-44677 eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseContro… Eladmin after 2.7 Fix from $2,3002024-09-10 MEDIUM 6.5 CVE-2024-45504 Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated atta… Mitigation only Fix from $1,6002024-09-10 MEDIUM 6.5 CVE-2024-7688 The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbit… Azindex after 0.8.1 Fix from $1,6002024-09-09 MEDIUM 6.8 CVE-2024-45172 An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is… C Mor Video Surveillance No fix yet Fix from $1,6002024-09-04 MEDIUM 6.1 CVE-2024-45527 REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and… Redcap No fix yet Fix from $1,6002024-09-02 HIGH 8.0 CVE-2024-42793 A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?ac… Music Management System No fix yet Fix from $1,9502024-08-28