Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.1 CVE-2023-7045 A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging… GitLab 16.10.6 / 16.11.3+ Fix from $1,6002024-05-23 HIGH 8.8 CVE-2024-35552 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataType… Idccms No fix yet Fix from $1,9502024-05-22 HIGH 8.3 CVE-2024-35553 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close. Idccms No fix yet Fix from $1,9502024-05-22 MEDIUM 5.4 CVE-2024-35554 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTy… Idccms No fix yet Fix from $1,6002024-05-22 MEDIUM 6.3 CVE-2024-35555 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=newsWeb&fie… Idccms No fix yet Fix from $1,6002024-05-22 HIGH 8.8 CVE-2024-35556 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet. Idccms No fix yet Fix from $1,9502024-05-22 MEDIUM 5.5 CVE-2024-35557 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close. Idccms No fix yet Fix from $1,6002024-05-22 HIGH 8.8 CVE-2024-35558 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close. Idccms No fix yet Fix from $1,9502024-05-22 HIGH 8.8 CVE-2024-35559 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close. Idccms No fix yet Fix from $1,9502024-05-22 MEDIUM 5.4 CVE-2024-35561 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close. Idccms No fix yet Fix from $1,6002024-05-22 MEDIUM 6.4 CVE-2024-35475 A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in… Openkm after 6.3.12 Fix from $1,6002024-05-22 MEDIUM 6.3 CVE-2024-35550 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=rev. Idccms No fix yet Fix from $1,6002024-05-22 HIGH 8.8 CVE-2024-36076 Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive info… Sysreptor 2024.40+ Fix from $1,9502024-05-19 HIGH 8.8 CVE-2024-23554 Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE). Bigfix Platform 9.5.25 / 10.0.12+ Fix from $1,9502024-05-18 HIGH 8.8 CVE-2024-27955 Cross-Site Request Forgery (CSRF) vulnerability in WP Automatic Automatic allows Privilege Escalation.This issue affects Automatic: from n/a through … Mitigation only Fix from $1,9502024-05-17 HIGH 7.1 CVE-2023-44478 Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affe… Mitigation only Fix from $1,9502024-05-17 MEDIUM 6.5 CVE-2024-34958 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add Idccms No fix yet Fix from $1,6002024-05-16 MEDIUM 5.4 CVE-2024-34957 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet. Idccms No fix yet Fix from $1,6002024-05-16 HIGH 8.8 CVE-2024-3643 The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins p… Newsletter Popup after 1.2 Fix from $1,9502024-05-16 MEDIUM 6.9 CVE-2024-3642 The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in ad… Newsletter Popup after 1.2 Fix from $1,6002024-05-16 MEDIUM 5.5 CVE-2024-3824 The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers … Base64 Encoder\/decoder after 0.9.2 Fix from $1,6002024-05-15 HIGH 8.8 CVE-2024-3406 The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make … Wp Prayer after 2.0.9 Fix from $1,9502024-05-15 MEDIUM 5.3 CVE-2024-3407 The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform un… Wp Prayer after 2.0.9 Fix from $1,6002024-05-15 HIGH 7.6 CVE-2024-3405 The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logg… Wp Prayer after 2.0.9 Fix from $1,9502024-05-15 HIGH 8.8 CVE-2024-35108 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homePro_deal.php?mudi=del&dataType=&dataTypeCN. Idccms No fix yet Fix from $1,9502024-05-15 MEDIUM 6.5 CVE-2024-35109 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&nohrefStr=close. Idccms No fix yet Fix from $1,6002024-05-15 MEDIUM 6.3 CVE-2024-35012 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=add&nohrefStr=close. Idccms No fix yet Fix from $1,6002024-05-14 HIGH 8.8 CVE-2024-35009 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=&fieldName=… Idccms No fix yet Fix from $1,9502024-05-14 HIGH 8.8 CVE-2024-35010 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&dataType=&dataTypeCN=%E5… Idccms No fix yet Fix from $1,9502024-05-14 MEDIUM 5.4 CVE-2024-35011 idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=rev&nohrefStr=close. Idccms No fix yet Fix from $1,6002024-05-14