Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2024-31205 Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attac… Saleor 3.14.64 / 3.15.39+ Fix from $1,6002024-04-08 MEDIUM 6.8 CVE-2023-49965 SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page. Mitigation only Fix from $1,6002024-04-05 HIGH 8.8 CVE-2024-2115 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. T… Learnpress 4.0.1+ Fix from $1,9502024-04-05 CRITICAL 9.1 CVE-2024-27448 MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing a… Mitigation only Fix from $2,3002024-04-05 HIGH 8.8 CVE-2024-29192 gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to Cross-Site Request Forgery. The `/api/config` endpoint allows o… Go2rtc after 1.8.5 Fix from $1,9502024-04-04 MEDIUM 5.4 CVE-2024-25692 There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthen… Portal For Arcgis after 11.1 Fix from $1,6002024-04-04 HIGH 8.8 CVE-2024-20368 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond… Identity Services Engine 3.1.0+ Fix from $1,9502024-04-03 MEDIUM 6.5 CVE-2024-20347 A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker… Emergency Responder 12.5+ Fix from $1,6002024-04-03 HIGH 8.8 CVE-2024-20281 A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticat… Nexus Dashboard 3.1 / 4.3+ Fix from $1,9502024-04-03 MEDIUM 6.8 CVE-2024-2322 The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to… Woocommerce Cart Abandonment Recovery 1.2.27+ Fix from $1,6002024-04-03 HIGH 7.1 CVE-2024-31105 Cross-Site Request Forgery (CSRF) vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a throu… Mitigation only Fix from $1,9502024-04-02 HIGH 7.1 CVE-2024-31109 Cross-Site Request Forgery (CSRF) vulnerability in Toastie Studio Woocommerce Social Media Share Buttons allows Stored XSS.This issue affects Woocomm… Mitigation only Fix from $1,9502024-04-02 HIGH 8.8 CVE-2024-30965 DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php. Dedecms Patch available Fix from $1,9502024-04-02 MEDIUM 5.5 CVE-2024-30946 DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php. Dedecms No fix yet Fix from $1,6002024-04-02 MEDIUM 6.5 CVE-2024-3135 A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when… Localai 2.17.0+ Fix from $1,6002024-04-01 MEDIUM 5.4 CVE-2024-31100 Cross-Site Request Forgery (CSRF) vulnerability in Festi-Team Popup Cart Lite for WooCommerce.This issue affects Popup Cart Lite for WooCommerce: fro… Mitigation only Fix from $1,6002024-03-31 HIGH 8.8 CVE-2024-1522 A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim'… Lollms Web Ui after 9.2 Fix from $1,9502024-03-30 HIGH 8.8 CVE-2024-30462 Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Prod… Husky Products Filter Professional For Woocommerce 1.3.5.2+ Fix from $1,9502024-03-29 HIGH 8.8 CVE-2024-30454 Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2. Wp Sms 6.6.3+ Fix from $1,9502024-03-29 MEDIUM 5.4 CVE-2024-30521 Cross-Site Request Forgery (CSRF) vulnerability in Landingi Landingi Landing Pages.This issue affects Landingi Landing Pages: from n/a through 3.1.1. No fix yet Fix from $1,6002024-03-29 HIGH 8.8 CVE-2024-30482 Cross-Site Request Forgery (CSRF) vulnerability in Brice CAPOBIANCO Simple Revisions Delete.This issue affects Simple Revisions Delete: from n/a thro… Simple Revisions Delete after 1.5.3 Fix from $1,9502024-03-29 HIGH 8.8 CVE-2024-30456 Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1. Wordpress Currency Switcher 1.2.0.2+ Fix from $1,9502024-03-29 HIGH 8.8 CVE-2024-30457 Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data… Wordpress Meta Data And Taxonomies Filter 1.3.3.2+ Fix from $1,9502024-03-29 HIGH 8.8 CVE-2024-30458 Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency S… Fox Currency Switcher Professional For Woocommerce 1.4.1.8+ Fix from $1,9502024-03-29 MEDIUM 5.4 CVE-2024-2969 The WP-Eggdrop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or … Wp Eggdrop Mitigation only Fix from $1,6002024-03-29 MEDIUM 6.1 CVE-2022-45850 Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro allows Stored XSS.This issue affects Image Map Pro: from n/a before 5.6.9. Mitigation only Fix from $1,6002024-03-28 MEDIUM 6.1 CVE-2024-28233 JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achiev… Jupyterhub 4.1.0+ Fix from $1,6002024-03-27 HIGH 7.1 CVE-2024-29773 Cross-Site Request Forgery (CSRF) vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint allows Cross-Site Scripting (XSS).This issue affects B… Mitigation only Fix from $1,9502024-03-27 HIGH 8.8 CVE-2023-39311 Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1. Fusion Builder after 3.11.1 Fix from $1,9502024-03-27 HIGH 8.8 CVE-2023-44999 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gatew… Stripe Payment Gateway after 7.6.0 Fix from $1,9502024-03-27