Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.1 CVE-2024-4328 A Cross-Site Request Forgery (CSRF) vulnerability exists in the clear_personality_files_list function of the parisneo/lollms-webui v9.6. The vulnerab… Lollms Web Ui No fix yet Fix from $1,9502024-06-10 MEDIUM 5.4 CVE-2024-35657 Cross-Site Request Forgery (CSRF) vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.6. Mitigation only Fix from $1,6002024-06-08 HIGH 8.8 CVE-2024-35689 Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.2.3. Analytify Google Analytics Dashboard 5.2.4+ Fix from $1,9502024-06-08 MEDIUM 5.4 CVE-2024-5003 The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could a… Wp Stacker after 1.8.5 Fix from $1,6002024-06-07 HIGH 8.3 CVE-2024-2288 A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms application, specifically in the p… Lollms Web Ui 9.3+ Fix from $1,9502024-06-06 HIGH 8.8 CVE-2024-1879 A Cross-Site Request Forgery (CSRF) vulnerability in significant-gravitas/autogpt version v0.5.0 allows attackers to execute arbitrary commands on th… Autogpt Classic Patch available Fix from $1,9502024-06-06 MEDIUM 5.4 CVE-2023-6968 The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.6.3. This is due to missi… The Moneytizer 10.0.1+ Fix from $1,6002024-06-06 HIGH 8.8 CVE-2024-36667 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/idcProType_deal.php?mudi=add&nohrefStr=close Idccms No fix yet Fix from $1,9502024-06-05 HIGH 8.8 CVE-2024-36668 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=del Idccms No fix yet Fix from $1,9502024-06-05 HIGH 8.8 CVE-2024-36669 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add. Idccms No fix yet Fix from $1,9502024-06-05 HIGH 8.8 CVE-2024-36670 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=del Idccms No fix yet Fix from $1,9502024-06-05 HIGH 8.8 CVE-2024-36547 idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add Idccms No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-36548 idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del Idccms No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-36549 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close Idccms No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-36550 idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close Idccms No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-34007 The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF. Moodle 4.3.4+ Fix from $1,9502024-05-31 HIGH 8.8 CVE-2024-34008 Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk. Moodle 4.1.10 / 4.2.7+ Fix from $1,9502024-05-31 HIGH 8.4 CVE-2024-34001 Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk. Moodle 4.1.10 / 4.2.7+ Fix from $1,9502024-05-31 MEDIUM 6.5 CVE-2024-4218 The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to plugin impr… Mitigation only Fix from $1,6002024-05-30 HIGH 7.3 CVE-2024-5185 The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result in the application becoming … Mitigation only Fix from $1,9502024-05-29 HIGH 7.4 CVE-2024-4429 Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure. Imanager 3.2.6+ Fix from $1,9502024-05-28 HIGH 7.1 CVE-2024-4531 The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perfor… Business Card No fix yet Fix from $1,9502024-05-27 MEDIUM 6.4 CVE-2024-4532 The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perfor… Business Card No fix yet Fix from $1,6002024-05-27 MEDIUM 6.1 CVE-2024-4534 The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, w… Kkprogressbar2 No fix yet Fix from $1,6002024-05-27 HIGH 8.8 CVE-2024-4535 The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF checks in some places, which could allow attackers to make logged in use… Kkprogressbar2 No fix yet Fix from $1,9502024-05-27 MEDIUM 5.0 CVE-2024-4529 The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perfor… Business Card No fix yet Fix from $1,6002024-05-27 MEDIUM 6.3 CVE-2024-4530 The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perfor… Business Card No fix yet Fix from $1,6002024-05-27 MEDIUM 5.7 CVE-2024-36255 Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attack… Mattermost Server 8.1.13 / 9.5.4+ Fix from $1,6002024-05-26 MEDIUM 6.1 CVE-2023-7045 A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging… GitLab 16.10.6 / 16.11.3+ Fix from $1,6002024-05-23 HIGH 8.8 CVE-2024-35552 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataType… Idccms No fix yet Fix from $1,9502024-05-22