Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.3 CVE-2024-3083 A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileg… Sensor Net Connect Firmware V2 Mitigation only Fix from $1,9502024-07-31 MEDIUM 6.5 CVE-2024-6412 The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform … Html Forms 1.3.34+ Fix from $1,6002024-07-31 MEDIUM 6.5 CVE-2023-38001 IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions… Aspera Orchestrator Mitigation only Fix from $1,6002024-07-30 HIGH 8.8 CVE-2024-7226 A vulnerability was found in SourceCodester Medicine Tracker System 1.0. It has been declared as problematic. This vulnerability affects unknown code… Medicine Tracker System No fix yet Fix from $1,9502024-07-30 MEDIUM 6.5 CVE-2024-6230 The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers… Pardakht Delkhah 2.9.9+ Fix from $1,6002024-07-30 HIGH 7.5 CVE-2024-40815 A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, … Ipados 10.6 / 13.6.8+ Fix from $1,9502024-07-29 MEDIUM 5.5 CVE-2024-5285 The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to ma… Wp Affiliate Platform 6.5.2+ Fix from $1,6002024-07-29 HIGH 8.8 CVE-2024-7169 A vulnerability classified as problematic has been found in SourceCodester School Fees Payment System 1.0. This affects an unknown part of the file /… School Fees Payment System No fix yet Fix from $1,9502024-07-28 MEDIUM 6.5 CVE-2024-7161 A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of the file /member.ph… Seacms No fix yet Fix from $1,6002024-07-28 MEDIUM 6.5 CVE-2024-6490 During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate… Master Slider 3.10.0+ Fix from $1,6002024-07-26 HIGH 8.8 CVE-2024-7106 A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admi… Spina after 2.18.0 Fix from $1,9502024-07-25 MEDIUM 5.4 CVE-2024-3246 The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to mi… Litespeed Cache 6.3+ Fix from $1,6002024-07-24 MEDIUM 6.5 CVE-2024-6751 The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to miss… Social Auto Poster 5.3.15+ Fix from $1,6002024-07-24 HIGH 8.8 CVE-2024-6244 The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users p… Pz Frontend Manager 1.0.6+ Fix from $1,9502024-07-22 MEDIUM 5.4 CVE-2024-6271 The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged… Community Events 1.5+ Fix from $1,6002024-07-22 HIGH 8.8 CVE-2024-41602 Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privileges via a crafted URL Spina Mitigation only Fix from $1,9502024-07-19 CRITICAL 9.6 CVE-2024-41603 Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout. Spina Mitigation only Fix from $2,3002024-07-19 HIGH 7.5 CVE-2023-7269 The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which c… Artplacer Widget after 2.21.1 Fix from $1,9502024-07-19 MEDIUM 6.1 CVE-2024-39090 The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cr… Online Shopping Portal No fix yet Fix from $1,6002024-07-18 HIGH 8.8 CVE-2024-39678 Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.1… Cooked 1.8.0+ Fix from $1,9502024-07-18 HIGH 8.8 CVE-2024-39679 Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and in… Cooked 1.8.0+ Fix from $1,9502024-07-18 HIGH 8.8 CVE-2024-39680 Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and in… Cooked 1.8.0+ Fix from $1,9502024-07-18 HIGH 8.8 CVE-2024-39681 Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and in… Cooked 1.8.0+ Fix from $1,9502024-07-18 HIGH 8.8 CVE-2024-40119 Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the pa… Mitigation only Fix from $1,9502024-07-17 MEDIUM 6.5 CVE-2024-5815 A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect … Enterprise Server 3.9.17 / 3.10.14+ Fix from $1,6002024-07-16 HIGH 8.8 CVE-2024-6075 The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged i… Wp Estore 8.5.5+ Fix from $1,9502024-07-15 MEDIUM 6.8 CVE-2024-5077 The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could a… Wp Emember 10.6.6+ Fix from $1,6002024-07-13 HIGH 8.1 CVE-2024-5167 The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the bla… Cm E Mail Blacklist 1.4.9+ Fix from $1,9502024-07-13 MEDIUM 6.8 CVE-2024-5284 The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi… Wp Affiliate Platform 6.5.1+ Fix from $1,6002024-07-13 HIGH 7.1 CVE-2024-5287 The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to … Wp Affiliate Platform 6.5.1+ Fix from $1,9502024-07-13