Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-31293 Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6. Easy Digital Downloads 3.2.7+ Fix from $1,9502024-04-12 HIGH 8.8 CVE-2024-31301 Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin –… Multiple Page Generator 3.4.1+ Fix from $1,9502024-04-12 HIGH 8.8 CVE-2024-31268 Cross-Site Request Forgery (CSRF) vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0. Apppresser 4.3.1+ Fix from $1,9502024-04-12 HIGH 8.8 CVE-2024-31269 Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps.This issue affects Easy Google Maps: from n/a through 1.11.11. Easy Google Maps 1.11.12+ Fix from $1,9502024-04-12 MEDIUM 6.3 CVE-2024-31272 Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through … Arforms Form Builder 1.6.2+ Fix from $1,6002024-04-12 MEDIUM 5.4 CVE-2024-31262 Cross-Site Request Forgery (CSRF) vulnerability in Jcodex WooCommerce Checkout Field Editor (Checkout Manager).This issue affects WooCommerce Checkou… Mitigation only Fix from $1,6002024-04-12 MEDIUM 5.4 CVE-2024-31263 Cross-Site Request Forgery (CSRF) vulnerability in aerin Loan Repayment Calculator and Application Form.This issue affects Loan Repayment Calculator … Mitigation only Fix from $1,6002024-04-12 HIGH 8.8 CVE-2024-31238 Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover.This issue affects Smart Online Order for Clover: from n/a t… Smart Online Order For Clover 1.5.6+ Fix from $1,9502024-04-12 MEDIUM 6.3 CVE-2024-22721 Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link. Form Tools No fix yet Fix from $1,6002024-04-11 MEDIUM 5.4 CVE-2024-31936 Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6. Mitigation only Fix from $1,6002024-04-11 HIGH 8.8 CVE-2024-32106 Cross-Site Request Forgery (CSRF) vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One].This issue affects WP Compress – Image Opti… Wp Compress 6.11.01+ Fix from $1,9502024-04-11 HIGH 8.8 CVE-2024-31932 Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28. Blocksy Companion 2.0.29+ Fix from $1,9502024-04-11 HIGH 7.1 CVE-2024-31285 Cross-Site Request Forgery (CSRF) vulnerability in Tooltip WordPress Tooltips allows Stored XSS.This issue affects WordPress Tooltips: from n/a throu… Mitigation only Fix from $1,9502024-04-11 HIGH 8.8 CVE-2024-25572 Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while loggin… Ninja Forms 3.4.31+ Fix from $1,9502024-04-11 HIGH 7.1 CVE-2024-2741 Cross-Site Request Forgery (CSRF) vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a r… Mitigation only Fix from $1,9502024-04-11 HIGH 8.1 CVE-2024-29019 ESPHome is a system to control microcontrollers remotely through Home Automation systems. API endpoints in dashboard component of ESPHome version 202… No fix yet Fix from $1,9502024-04-11 HIGH 8.8 CVE-2024-27967 Cross-Site Request Forgery (CSRF) vulnerability in Michael Leithold DSGVO All in one for WP.This issue affects DSGVO All in one for WP: from n/a thro… Dsgvo All In One For Wp 4.4+ Fix from $1,9502024-04-11 HIGH 8.8 CVE-2024-31988 XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime edi… Xwiki 14.10.19 / 15.5.4+ Fix from $1,9502024-04-10 MEDIUM 5.4 CVE-2024-31985 XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/… Xwiki 14.10.19 / 15.5.4+ Fix from $1,6002024-04-10 HIGH 8.8 CVE-2024-31986 XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with… Xwiki 14.10.19 / 15.5.4+ Fix from $1,9502024-04-10 HIGH 8.8 CVE-2024-31430 Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Edi… Bear Woocommerce Bulk Editor And Products Manager Professional 1.0.8.2 / 1.1.4.2+ Fix from $1,9502024-04-10 HIGH 7.1 CVE-2024-31299 Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation allows Cross-Site Scripting (XSS).This issue affects… Mitigation only Fix from $1,9502024-04-10 HIGH 8.8 CVE-2024-2196 aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stea… Aim No fix yet Fix from $1,9502024-04-10 MEDIUM 5.2 CVE-2024-23734 Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket al… S Notify 2.0.1+ Fix from $1,6002024-04-10 HIGH 8.8 CVE-2024-27474 Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on beha… Leantime No fix yet Fix from $1,9502024-04-10 HIGH 8.8 CVE-2024-2125 The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… Envialosimple 2.4+ Fix from $1,9502024-04-09 HIGH 8.8 CVE-2024-1315 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … Classified Listing 3.0.5+ Fix from $1,9502024-04-09 MEDIUM 5.4 CVE-2021-28656 Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue aff… Zeppelin after 0.9.0 Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-31369 Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. Soledad 8.4.6+ Fix from $1,6002024-04-09 MEDIUM 6.0 CVE-2024-27631 Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php Savane 3.13+ Fix from $1,6002024-04-08