Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2024-33680 Cross-Site Request Forgery (CSRF) vulnerability in MainWP MainWP Child Reports.This issue affects MainWP Child Reports: from n/a through 2.1.1. Mainwp Child Reports 2.2+ Fix from $1,6002024-04-26 HIGH 8.8 CVE-2024-33651 Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : from n/a through 1.2.1. Mf Gig Calendar after 1.2.1 Fix from $1,9502024-04-26 MEDIUM 5.4 CVE-2024-33638 Cross-Site Request Forgery (CSRF) vulnerability in Brijesh Kothari Smart Maintenance Mode.This issue affects Smart Maintenance Mode: from n/a through… Mitigation only Fix from $1,6002024-04-26 MEDIUM 5.4 CVE-2024-3058 The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which cou… Enl Newsletter after 1.0.1 Fix from $1,6002024-04-26 MEDIUM 5.7 CVE-2024-3059 The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins dele… Enl Newsletter after 1.0.1 Fix from $1,6002024-04-26 CRITICAL 9.6 CVE-2024-30560 Cross-Site Request Forgery (CSRF) vulnerability in 大侠WP DX-Watermark.This issue affects DX-Watermark: from n/a through 1.0.4. Mitigation only Fix from $2,3002024-04-25 HIGH 7.1 CVE-2024-32958 Cross-Site Request Forgery (CSRF) vulnerability in Giorgos Sarigiannidis Slash Admin allows Cross-Site Scripting (XSS).This issue affects Slash Admin… Mitigation only Fix from $1,9502024-04-24 HIGH 8.8 CVE-2024-32793 Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. Paid Memberships Pro 3.0+ Fix from $1,9502024-04-24 HIGH 8.8 CVE-2024-32794 Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. Paid Memberships Pro 3.0+ Fix from $1,9502024-04-24 MEDIUM 6.1 CVE-2024-32785 Cross-Site Request Forgery (CSRF) vulnerability in Webangon The Pack Elementor addons allows Cross-Site Scripting (XSS).This issue affects The Pack E… The Pack Elementor Addons 2.0.8.4+ Fix from $1,6002024-04-24 HIGH 7.1 CVE-2024-32789 Cross-Site Request Forgery (CSRF) vulnerability in Seers allows Cross-Site Scripting (XSS).This issue affects Seers: from n/a through 8.1.0. Mitigation only Fix from $1,9502024-04-24 MEDIUM 6.5 CVE-2024-1756 The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated use… Woocommerce Customers Manager 29.8+ Fix from $1,6002024-04-24 HIGH 7.6 CVE-2024-32693 Cross-Site Request Forgery (CSRF) vulnerability in ValvePress Automatic.This issue affects Automatic: from n/a before 3.93.0. Mitigation only Fix from $1,9502024-04-22 MEDIUM 6.5 CVE-2024-32538 Cross-Site Request Forgery (CSRF) vulnerability in Joshua Eldridge Easy CountDowner allows Stored XSS.This issue affects Easy CountDowner: from n/a t… Mitigation only Fix from $1,6002024-04-17 HIGH 7.1 CVE-2024-32550 Cross-Site Request Forgery (CSRF) vulnerability in BMI Adult & Kid Calculator allows Stored XSS.This issue affects BMI Adult & Kid Calculator: from n… Mitigation only Fix from $1,9502024-04-17 HIGH 7.1 CVE-2024-32549 Cross-Site Request Forgery (CSRF) vulnerability in Microkid Related Posts for WordPress allows Cross-Site Scripting (XSS).This issue affects Related … Mitigation only Fix from $1,9502024-04-17 HIGH 7.5 CVE-2024-31503 Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CS… Dolibarr Erp\/crm 19.0.1+ Fix from $1,9502024-04-17 MEDIUM 6.1 CVE-2024-21044 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a… Complex Maintenance Repair And Overhaul after 12.2.13 Fix from $1,6002024-04-16 MEDIUM 6.1 CVE-2024-21043 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a… Complex Maintenance Repair And Overhaul after 12.2.13 Fix from $1,6002024-04-16 MEDIUM 6.1 CVE-2024-21032 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a… Complex Maintenance Repair And Overhaul after 12.2.13 Fix from $1,6002024-04-16 MEDIUM 6.1 CVE-2024-21020 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a… Complex Maintenance Repair And Overhaul after 12.2.13 Fix from $1,6002024-04-16 HIGH 8.8 CVE-2024-3782 Cross-Site Request Forgery vulnerability in WBSAirback 21.02.04, which could allow an attacker to create a manipulated HTML form to perform privilege… Wbsairback Mitigation only Fix from $1,9502024-04-15 MEDIUM 5.4 CVE-2024-31389 Cross-Site Request Forgery (CSRF) vulnerability in Ertano MihanPanel.This issue affects MihanPanel: from n/a before 12.7. Mitigation only Fix from $1,6002024-04-15 HIGH 8.8 CVE-2024-31374 Cross-Site Request Forgery (CSRF) vulnerability in Scott Bolinger AppPresser apppresser allows Cross Site Request Forgery.This issue affects AppPress… Apppresser 4.3.1+ Fix from $1,9502024-04-15 HIGH 8.8 CVE-2024-31378 Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp Forms by MailMunch: from n/a t… Mailchimp Forms 3.2.2+ Fix from $1,9502024-04-15 HIGH 8.8 CVE-2024-31382 Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.22. Blocksy 2.0.23+ Fix from $1,9502024-04-15 MEDIUM 5.4 CVE-2024-31373 Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf e2pdf e2pdf.This issue affects e2pdf: from n/a through <= 1.20.27. E2pdf 1.23.00+ Fix from $1,6002024-04-15 MEDIUM 5.4 CVE-2024-31933 Cross-Site Request Forgery (CSRF) vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: fro… Mitigation only Fix from $1,6002024-04-15 HIGH 8.8 CVE-2024-31429 Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Sarada Lite.This issue affects Sarada Lite: from n/a through 1.1.2. Sarada 1.1.3+ Fix from $1,9502024-04-15 MEDIUM 5.4 CVE-2024-31434 Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0… Mitigation only Fix from $1,6002024-04-15