Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-42616 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statis… Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42617 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32 Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42618 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42621 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42603 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42604 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3 Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42608 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php. Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42583 A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42584 A Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42585 A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42586 A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42576 A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42577 A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.0 CVE-2024-42578 A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42579 A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42580 A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42581 A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42582 A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. Warehouse Inventory System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42553 A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate priv… Hotel Management System after 2020-06-10 Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42555 A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate pr… Hotel Management System after 2020-06-10 Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42557 A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate pri… Hotel Management System after 2020-06-10 Fix from $1,9502024-08-20 MEDIUM 6.1 CVE-2024-7850 The BP Profile Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.7.5. This is due to mi… Mitigation only Fix from $1,6002024-08-20 MEDIUM 6.5 CVE-2024-42475 In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. Thes… Mitigation only Fix from $1,6002024-08-15 MEDIUM 6.5 CVE-2024-42476 In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `state` parameter to prevent cro… Mitigation only Fix from $1,6002024-08-15 MEDIUM 6.5 CVE-2024-7420 The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due… Insert Php Code Snippet 1.3.7+ Fix from $1,6002024-08-15 HIGH 7.1 CVE-2024-38724 Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Muham… Mitigation only Fix from $1,9502024-08-13 HIGH 8.8 CVE-2024-42624 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10. Frogcms No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42625 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add Frogcms No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42626 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add. Frogcms No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42627 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3. Frogcms No fix yet Fix from $1,9502024-08-12