Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2024-5028 The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to mak… Cm Search And Replace 1.3.9+ Fix from $1,6002024-07-13 MEDIUM 5.9 CVE-2024-5033 The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow a… Sully 4.3.1+ Fix from $1,6002024-07-13 HIGH 8.8 CVE-2024-5034 The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwante… Sully 4.3.1+ Fix from $1,9502024-07-13 HIGH 8.8 CVE-2024-5076 The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform u… Wp Emember 10.6.6+ Fix from $1,9502024-07-13 MEDIUM 6.8 CVE-2024-3632 The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, which could allow attackers to m… Smart Image Gallery 1.0.19+ Fix from $1,6002024-07-13 HIGH 7.4 CVE-2024-37940 Cross-Site Request Forgery (CSRF) vulnerability in Seraphinite Solutions Seraphinite Accelerator (Full, premium).This issue affects Seraphinite Accel… Mitigation only Fix from $1,9502024-07-12 HIGH 7.1 CVE-2024-37213 Cross-Site Request Forgery (CSRF) vulnerability in guru-aliexpress AliNext ali2woo-lite allows Cross Site Request Forgery.This issue affects AliNext:… Mitigation only Fix from $1,9502024-07-12 HIGH 7.1 CVE-2024-35773 Cross-Site Request Forgery (CSRF) vulnerability in WPJohnny, zerOneIT Comment Reply Email allows Cross-Site Scripting (XSS).This issue affects Commen… Mitigation only Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-6023 The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in … Contentlock 1.0.4+ Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-6024 The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make … Contentlock 1.0.4+ Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-6022 The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a lo… Contentlock 1.0.4+ Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-1845 The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to ma… Vikrentcar 1.3.2+ Fix from $1,9502024-07-11 MEDIUM 6.5 CVE-2024-6649 A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vu… Employee And Visitor Gate Pass Logging System No fix yet Fix from $1,6002024-07-10 HIGH 8.8 CVE-2024-40331 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup Idccms No fix yet Fix from $1,9502024-07-10 HIGH 8.8 CVE-2024-40332 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord Idccms Mitigation only Fix from $1,9502024-07-10 HIGH 8.8 CVE-2024-28828 Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site. Checkmk Mitigation only Fix from $1,9502024-07-10 MEDIUM 6.3 CVE-2024-40328 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.php?mudi=del&dataType=&dataID=6 Idccms No fix yet Fix from $1,6002024-07-10 HIGH 8.8 CVE-2024-40329 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup Idccms No fix yet Fix from $1,9502024-07-10 HIGH 8.8 CVE-2024-40334 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3 Idccms No fix yet Fix from $1,9502024-07-10 HIGH 8.7 CVE-2024-3798 Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker… Mitigation only Fix from $1,9502024-07-10 HIGH 8.8 CVE-2024-39063 Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests… Limesurvey after 6.5.12 Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-40034 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=del Idccms No fix yet Fix from $1,9502024-07-09 MEDIUM 5.9 CVE-2024-40035 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=add. Idccms No fix yet Fix from $1,6002024-07-09 HIGH 8.8 CVE-2024-40037 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=del Idccms No fix yet Fix from $1,9502024-07-09 MEDIUM 5.3 CVE-2024-40038 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=rev Idccms No fix yet Fix from $1,6002024-07-09 HIGH 8.8 CVE-2024-40039 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userGroup_deal.php?mudi=del Idccms No fix yet Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-27783 Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attack… Fortiaiops Mitigation only Fix from $1,9502024-07-09 MEDIUM 5.3 CVE-2024-4100 The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missin… Mitigation only Fix from $1,6002024-07-09 HIGH 8.8 CVE-2024-6316 The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, an… Generate Pdf Using Contact Form 7 4.1.3+ Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-6317 The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, an… Generate Pdf Using Contact Form 7 4.1.3+ Fix from $1,9502024-07-09