Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-42623 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1 Frogcms No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42630 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file. Frogcms No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42631 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1. Frogcms No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42632 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add. Frogcms No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42628 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3. Frogcms No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-42629 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10. Frogcms No fix yet Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-7661 A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been classified as problematic. This affects the functio… Car Driving School Management System No fix yet Fix from $1,9502024-08-12 MEDIUM 6.5 CVE-2024-7662 A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. This vulnerability affects… Car Driving School Management System No fix yet Fix from $1,6002024-08-12 MEDIUM 5.4 CVE-2024-7645 A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects un… Clinic\'s Patient Management System No fix yet Fix from $1,6002024-08-12 MEDIUM 6.1 CVE-2024-7574 The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.5. This is due to missing no… Christmasify\! 1.5.6+ Fix from $1,6002024-08-12 MEDIUM 5.4 CVE-2024-6136 The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged i… Wp Estore 8.5.6+ Fix from $1,6002024-08-12 HIGH 8.8 CVE-2024-40488 A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the… Live Membership System No fix yet Fix from $1,9502024-08-12 HIGH 8.0 CVE-2024-40476 A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacke… Best House Rental Management Mitigation only Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-7492 The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to m… Mainwp Child 2.2.1+ Fix from $1,9502024-08-08 HIGH 8.8 CVE-2024-6720 The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform u… Light Poll after 1.0.0 Fix from $1,9502024-08-06 MEDIUM 6.1 CVE-2024-5081 The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could … Wp Emember 10.7.0+ Fix from $1,6002024-08-05 HIGH 8.1 CVE-2024-2232 The lacks CSRF checks allowing a user to invite any user to any group (including private groups) Himer 2.1.3+ Fix from $1,9502024-08-05 HIGH 8.8 CVE-2024-7460 A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unk… Warehouse Inventory System No fix yet Fix from $1,9502024-08-04 HIGH 8.8 CVE-2024-7459 A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the… Warehouse Inventory System No fix yet Fix from $1,9502024-08-04 HIGH 7.1 CVE-2024-38776 Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This issue affects WP GoToWebinar: … Mitigation only Fix from $1,9502024-08-02 HIGH 8.8 CVE-2024-3238 The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… Mitigation only Fix from $1,9502024-08-02 HIGH 8.8 CVE-2024-7367 A vulnerability, which was classified as problematic, was found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of th… Simple Realtime Quiz System No fix yet Fix from $1,9502024-08-01 HIGH 8.8 CVE-2024-32863 Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF) Exacqvision Web Service after 24.03 Fix from $1,9502024-08-01 HIGH 8.8 CVE-2024-7360 A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. This affects an unknown part of… Tracking Monitoring Management System No fix yet Fix from $1,9502024-08-01 HIGH 8.8 CVE-2024-6040 In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities.… Lollms Web Ui No fix yet Fix from $1,9502024-08-01 MEDIUM 6.5 CVE-2024-2843 The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged i… Woocommerce Customers Manager 30.1+ Fix from $1,6002024-08-01 HIGH 8.1 CVE-2024-3983 The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make lo… Woocommerce Customers Manager 30.1+ Fix from $1,9502024-08-01 MEDIUM 6.5 CVE-2024-6496 The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers to make logged in users perf… Light Poll after 1.0.0 Fix from $1,6002024-08-01 MEDIUM 6.5 CVE-2024-1747 The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticat… Woocommerce Customers Manager 30.2+ Fix from $1,6002024-08-01 HIGH 8.8 CVE-2024-40883 Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product wit… Wrc 2533gs2 B Firmware 1.12 / 1.69+ Fix from $1,9502024-08-01