Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.1 CVE-2024-20986 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Mitigation only Fix from $1,6002024-02-17 MEDIUM 6.1 CVE-2024-20933 Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are aff… Installed Base after 12.2.13 Fix from $1,6002024-02-17 MEDIUM 6.5 CVE-2024-20718 Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result … Commerce Mitigation only Fix from $1,6002024-02-15 MEDIUM 6.5 CVE-2024-23785 Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remot… Jh Rvb1 Firmware Mitigation only Fix from $1,6002024-02-14 MEDIUM 6.8 CVE-2024-21381 Microsoft Azure Active Directory B2C Spoofing Vulnerability Azure Active Directory Patch available Fix from $1,6002024-02-13 HIGH 8.8 CVE-2024-25914 Cross-Site Request Forgery (CSRF) vulnerability in Photoboxone SMTP Mail.This issue affects SMTP Mail: from n/a through 1.3.20. Smtp Mail after 1.3.20 Fix from $1,9502024-02-13 HIGH 8.8 CVE-2023-52431 The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an… \ 0.0.19+ Fix from $1,9502024-02-13 MEDIUM 5.4 CVE-2023-6499 The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could all… Lastunes after 3.6.1 Fix from $1,6002024-02-12 HIGH 8.8 CVE-2024-24875 Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13. Link Library after 7.5.13 Fix from $1,9502024-02-12 HIGH 8.8 CVE-2024-24884 Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.… Contact Form 7 Connector after 1.2.2 Fix from $1,9502024-02-12 HIGH 8.8 CVE-2024-24887 Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Vot… Contest Gallery 21.2.9+ Fix from $1,9502024-02-12 HIGH 8.8 CVE-2024-24929 Cross-Site Request Forgery (CSRF) vulnerability in Ryan Duff, Peter Westwood WP Contact Form.This issue affects WP Contact Form: from n/a through 1.6. Wp Contact Form after 1.6 Fix from $1,9502024-02-12 HIGH 8.8 CVE-2024-24935 Cross-Site Request Forgery (CSRF) vulnerability in WpSimpleTools Basic Log Viewer.This issue affects Basic Log Viewer: from n/a through 1.0.4. Basic Log Viewer after 1.0.4 Fix from $1,9502024-02-12 HIGH 8.8 CVE-2024-25417 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php. Flusity No fix yet Fix from $1,9502024-02-11 HIGH 8.8 CVE-2024-25418 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php. Flusity No fix yet Fix from $1,9502024-02-11 HIGH 8.8 CVE-2024-25419 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php. Flusity No fix yet Fix from $1,9502024-02-11 HIGH 8.8 CVE-2023-50349 Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to… Sametime 12.0.2+ Fix from $1,9502024-02-09 HIGH 8.8 CVE-2024-24819 icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base… Icingaweb2 Module Incubator 0.22.0+ Fix from $1,9502024-02-09 HIGH 8.3 CVE-2024-24820 Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate … Icinga 1.8.2 / 1.9.2+ Fix from $1,9502024-02-09 HIGH 8.8 CVE-2023-47020 Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafte… Terminal Handler No fix yet Fix from $1,9502024-02-08 HIGH 8.8 CVE-2024-20254 Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote at… Expressway after 15.0 Fix from $1,9502024-02-07 HIGH 7.1 CVE-2024-20255 A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote a… Expressway 15.0+ Fix from $1,9502024-02-07 HIGH 8.8 CVE-2024-20252 Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote at… Expressway after 15.0 Fix from $1,9502024-02-07 HIGH 8.8 CVE-2023-38579 The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which cou… L206 F2g Firmware Mitigation only Fix from $1,9502024-02-06 HIGH 8.8 CVE-2024-24593 A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a … Clearml after 1.14.1 Fix from $1,9502024-02-06 HIGH 8.8 CVE-2024-0428 The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3. This is due to missing or… Index Now after 2.6.3 Fix from $1,9502024-02-05 HIGH 8.8 CVE-2024-24468 Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php. Flusity No fix yet Fix from $1,9502024-02-05 HIGH 8.8 CVE-2024-24469 Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php. Flusity No fix yet Fix from $1,9502024-02-05 HIGH 7.5 CVE-2024-23831 LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker… Ledgersmb 1.10.30 / 1.11.9+ Fix from $1,9502024-02-02 HIGH 8.8 CVE-2024-24470 Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component. Flusity No fix yet Fix from $1,9502024-02-02