Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-6320 The ScrollTo Top plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 1.2.2. T… Mitigation only Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-6321 The ScrollTo Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 1.1.1… Mitigation only Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-6309 The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and… Mitigation only Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-6310 The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and includ… Mitigation only Fix from $1,9502024-07-09 MEDIUM 5.4 CVE-2024-37923 Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.This issue affects Cliengo – C… Mitigation only Fix from $1,6002024-07-09 HIGH 8.8 CVE-2023-47677 A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially … Rtl819x Jungle Software Development Kit No fix yet Fix from $1,9502024-07-08 MEDIUM 6.5 CVE-2024-40601 An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules. Mediawiki after 1.42.1 Fix from $1,6002024-07-07 MEDIUM 5.4 CVE-2024-39021 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApiData_deal.php?mudi=del Idccms No fix yet Fix from $1,6002024-07-05 HIGH 8.8 CVE-2024-39022 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mudi=deal Idccms No fix yet Fix from $1,9502024-07-05 HIGH 8.8 CVE-2024-39023 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=add&nohrefStr=close Idccms No fix yet Fix from $1,9502024-07-05 MEDIUM 5.4 CVE-2024-39019 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/idcProData_deal.php?mudi=del Idccms No fix yet Fix from $1,6002024-07-05 MEDIUM 6.3 CVE-2024-39020 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/vpsApiData_deal.php?mudi=rev&nohrefStr=close Idccms No fix yet Fix from $1,6002024-07-05 MEDIUM 6.5 CVE-2024-27717 Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate priv… Eskooly after 3.0 Fix from $1,6002024-07-05 HIGH 8.8 CVE-2024-5943 The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing… Nested Pages 3.2.8+ Fix from $1,9502024-07-04 MEDIUM 5.4 CVE-2024-38344 A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is exploited, an attacker allows a… Mitigation only Fix from $1,6002024-07-04 HIGH 8.1 CVE-2024-38345 A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allow… Mitigation only Fix from $1,9502024-07-04 HIGH 8.8 CVE-2024-2376 The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform … Wpqa Builder 6.1.1+ Fix from $1,9502024-07-03 MEDIUM 5.4 CVE-2024-39119 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=close. Idccms No fix yet Fix from $1,6002024-07-02 HIGH 8.8 CVE-2024-5767 The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allo… Sitetweet after 0.2 Fix from $1,9502024-07-02 HIGH 8.8 CVE-2024-23736 Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME cert… Mitigation only Fix from $1,9502024-07-01 MEDIUM 5.4 CVE-2024-23737 Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user… S Notify 2.0.1 / 4.0.2+ Fix from $1,6002024-07-01 HIGH 8.8 CVE-2024-31902 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize… Infosphere Information Server Mitigation only Fix from $1,9502024-06-30 MEDIUM 5.4 CVE-2024-6405 The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due t… Floating Social Buttons after 1.5 Fix from $1,6002024-06-29 HIGH 8.1 CVE-2024-5712 A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerabilit… Devika No fix yet Fix from $1,9502024-06-28 MEDIUM 5.4 CVE-2024-5935 A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the ser… Privategpt No fix yet Fix from $1,6002024-06-27 HIGH 8.8 CVE-2024-39158 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet. Idccms No fix yet Fix from $1,9502024-06-27 HIGH 8.8 CVE-2024-39154 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeC… Idccms No fix yet Fix from $1,9502024-06-27 MEDIUM 6.8 CVE-2024-39155 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=add. Idccms No fix yet Fix from $1,6002024-06-27 HIGH 7.6 CVE-2024-4758 The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to m… Muslim Prayer Time Bd 2.5+ Fix from $1,9502024-06-26 HIGH 8.1 CVE-2024-4757 The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, … Logo Manager For Enamad after 0.7 Fix from $1,9502024-06-25