Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-23510 Cross-Site Request Forgery (CSRF) vulnerability in Martyn Chamberlin Don't Muck My Markup.This issue affects Don't Muck My Markup: from n/a through 1… Dont Muck My Markup after 1.8 Fix from $1,9502024-03-27 MEDIUM 5.4 CVE-2024-23515 Cross-Site Request Forgery (CSRF) vulnerability in Cincopa Post Video Players.This issue affects Post Video Players: from n/a through 1.159. Mitigation only Fix from $1,6002024-03-27 MEDIUM 6.1 CVE-2022-45847 Cross-Site Request Forgery (CSRF) vulnerability in WPAssist.Me WordPress Countdown Widget allows Cross-Site Scripting (XSS).This issue affects WordPr… Countdown Widget after 3.1.9.1 Fix from $1,6002024-03-27 CRITICAL 9.8 CVE-2024-29684 DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attack… Dedecms No fix yet Fix from $2,3002024-03-26 HIGH 8.8 CVE-2024-2904 Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through 1.0.33. Calliope 1.0.35+ Fix from $1,9502024-03-26 MEDIUM 6.5 CVE-2023-51416 Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/a through 2.2. Mitigation only Fix from $1,6002024-03-26 MEDIUM 6.8 CVE-2024-1231 The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins… Cm Download Manager 2.9.0+ Fix from $1,6002024-03-25 HIGH 8.8 CVE-2024-1962 The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins… Cm Download Manager 2.9.1+ Fix from $1,9502024-03-25 MEDIUM 6.1 CVE-2024-29009 Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker to hijack the authentication… Mitigation only Fix from $1,6002024-03-25 HIGH 7.4 CVE-2024-29499 Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2. Anchor Cms No fix yet Fix from $1,9502024-03-22 HIGH 7.5 CVE-2024-2449EPSS 13% A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the I… Loadmaster 7.2.54.9 / 7.2.59.3+ Fix from $1,9502024-03-22 MEDIUM 6.5 CVE-2024-2816 A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. Affected by this vulnerability is the function fromSysToolReboot of th… Ac15 Firmware No fix yet Fix from $1,6002024-03-22 MEDIUM 6.5 CVE-2024-2817 A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. Affected by this issue is the function fromSysToolRes… Ac15 Firmware No fix yet Fix from $1,6002024-03-22 HIGH 8.3 CVE-2024-25808 Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album f… Lychee No fix yet Fix from $1,9502024-03-22 MEDIUM 6.1 CVE-2024-27968 Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for… Super Page Cache after 4.7.5 Fix from $1,6002024-03-21 HIGH 8.8 CVE-2024-1538EPSS 11% The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing… File Manager 7.2.5+ Fix from $1,9502024-03-21 CRITICAL 9.1 CVE-2024-29026 Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS … Owncast after 0.1.2 Fix from $2,3002024-03-20 HIGH 8.8 CVE-2024-0856 The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged … Appointment Booking Calendar 1.3.83+ Fix from $1,9502024-03-20 MEDIUM 5.4 CVE-2024-1785 The Contests by Rewards Fuel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.62. This is d… Mitigation only Fix from $1,6002024-03-20 HIGH 8.1 CVE-2024-24336 A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endpoints within Koha Library Man… Mitigation only Fix from $1,9502024-03-19 MEDIUM 6.5 CVE-2024-27439 An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wick… Wicket 9.17.0+ Fix from $1,6002024-03-19 HIGH 8.8 CVE-2024-0779 The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to … Enjoy Social Feed after 6.2.2 Fix from $1,9502024-03-18 HIGH 8.8 CVE-2024-0858 The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform … Innovs Hr after 1.0.3.4 Fix from $1,9502024-03-18 MEDIUM 6.1 CVE-2024-22475 Cross-site request forgery vulnerability in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. … Mitigation only Fix from $1,6002024-03-18 MEDIUM 6.3 CVE-2024-27974 Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet Services allows a remote unaut… Mitigation only Fix from $1,6002024-03-18 MEDIUM 6.5 CVE-2024-2559 A vulnerability classified as problematic has been found in Tenda AC18 15.03.05.05. Affected is the function fromSysToolReboot of the file /goform/Sy… Ac18 Firmware Mitigation only Fix from $1,6002024-03-17 MEDIUM 6.1 CVE-2024-27194 Cross-Site Request Forgery (CSRF) vulnerability in Andrei Ivasiuc Fontific | Google Fonts allows Stored XSS.This issue affects Fontific | Google Font… Fontific after 0.1.6 Fix from $1,6002024-03-16 HIGH 7.1 CVE-2024-27195 Cross-Site Request Forgery (CSRF) vulnerability in sverde1 Watermark RELOADED watermark-reloaded allows Cross Site Request Forgery.This issue affects… Mitigation only Fix from $1,9502024-03-16 HIGH 7.1 CVE-2024-27197 Cross-Site Request Forgery (CSRF) vulnerability in Bee BeePress allows Stored XSS.This issue affects BeePress: from n/a through 6.9.8. Mitigation only Fix from $1,9502024-03-16 HIGH 8.8 CVE-2023-51474 Cross-Site Request Forgery (CSRF) vulnerability in Pixelemu TerraClassifieds.This issue affects TerraClassifieds: from n/a through 2.0.3. Mitigation only Fix from $1,9502024-03-16