Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.5 CVE-2026-46955 Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected are 12.2.3-… Human Resources after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.0 CVE-2026-46894 Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affected are 12.… Isupplier Portal after 12.2.15 Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2026-46869 Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 and… Mysql Shell after 9.7.0 Fix from $1,6002026-06-17 CRITICAL 9.3 CVE-2026-46785 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect… Webcenter Content Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.6 CVE-2026-46786 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect… Webcenter Content Mitigation only Fix from $2,3002026-06-17 HIGH 8.0 CVE-2026-46787 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect… Webcenter Content Mitigation only Fix from $1,9502026-06-17 MEDIUM 5.3 CVE-2016-20083 WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabli… No fix yet Fix from $1,6002026-06-15 HIGH 7.1 CVE-2026-49396 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.0.14, cross-si… Mitigation only Fix from $1,9502026-06-12 HIGH 7.1 CVE-2026-54359 MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled,… Patch available Fix from $1,9502026-06-12 HIGH 8.0 CVE-2026-48612 Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to… Mitigation only Fix from $1,9502026-06-12 HIGH 8.8 CVE-2025-58468 A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerab… Notification Center 1.10.0.3291+ Fix from $1,9502026-06-10 MEDIUM 6.3 CVE-2026-39170 SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php. Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-8907 The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing no… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-8910 The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to m… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-11270 Inappropriate implementation in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a craft… Chrome 149.0.7827.53+ Fix from $1,6002026-06-05 HIGH 7.5 CVE-2026-11265 Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HT… Chrome 149.0.7827.53+ Fix from $1,9502026-06-05 MEDIUM 6.5 CVE-2026-11214 Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11200 Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11194 Inappropriate implementation in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTM… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11195 Inappropriate implementation in MHTML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11148 Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11139 Inappropriate implementation in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11134 Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11129 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11106 Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11083 Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a cr… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11084 Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a cr… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11020 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 8.8 CVE-2026-43985 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing adm… Mitigation only Fix from $1,9502026-06-04 CRITICAL 9.8 CVE-2019-25729 PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting P… Mitigation only Fix from $2,3002026-06-04