Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2023-6676 Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery. This issue aff… Cybermath Mitigation only Fix from $1,9502024-02-02 HIGH 8.8 CVE-2024-24524 Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php compone… Flusity No fix yet Fix from $1,9502024-02-02 HIGH 8.8 CVE-2024-22859 Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. N… Livewire 3.0.4+ Fix from $1,9502024-02-01 HIGH 8.8 CVE-2024-22136 Cross-Site Request Forgery (CSRF) vulnerability in DroitThemes Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder.This… Droit Elementor Addons after 3.1.5 Fix from $1,9502024-01-31 HIGH 8.8 CVE-2024-22140 Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0. Profile Builder after 3.10.0 Fix from $1,9502024-01-31 HIGH 8.8 CVE-2024-22143 Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check.This issue affects WP Spell Check: from n/a through 9.17. Wpspellcheck after 9.17 Fix from $1,9502024-01-31 HIGH 8.8 CVE-2024-22285 Cross-Site Request Forgery (CSRF) vulnerability in Elise Bosse Frontpage Manager.This issue affects Frontpage Manager: from n/a through 1.3. Frontpage Manager after 1.3 Fix from $1,9502024-01-31 HIGH 8.8 CVE-2024-22291 Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3. Browser Theme Color after 1.3 Fix from $1,9502024-01-31 HIGH 8.8 CVE-2024-22304 Cross-Site Request Forgery (CSRF) vulnerability in Borbis Media FreshMail For WordPress.This issue affects FreshMail For WordPress: from n/a through … Freshmail For Wordpress after 2.3.2 Fix from $1,9502024-01-31 MEDIUM 6.1 CVE-2024-22287 Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS).This issue affects Better Anc… Better Anchor Links after 1.7.5 Fix from $1,6002024-01-31 HIGH 8.8 CVE-2024-22290 Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affe… Custom Dashboard Widgets after 1.3.1 Fix from $1,9502024-01-31 MEDIUM 6.5 CVE-2024-22643 A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets. Seo Panel No fix yet Fix from $1,6002024-01-30 MEDIUM 6.5 CVE-2023-51813 Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary c… Free And Open Source Inventory Management System No fix yet Fix from $1,6002024-01-30 HIGH 8.8 CVE-2023-6390 The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a … Wordpress Users after 1.4.0 Fix from $1,9502024-01-29 HIGH 8.8 CVE-2023-6391 The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a … Custom User Css after 0.2 Fix from $1,9502024-01-29 MEDIUM 5.4 CVE-2023-6503 The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which c… Wp Plugin Lister after 2.1.0 Fix from $1,6002024-01-29 HIGH 8.8 CVE-2023-6946 The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a … Autotitle after 1.0.3 Fix from $1,9502024-01-29 HIGH 8.8 CVE-2023-7074 The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to… Wp Social Bookmark Menu after 1.2 Fix from $1,9502024-01-29 MEDIUM 6.3 CVE-2024-0667 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… Form Maker after 1.15.21 Fix from $1,6002024-01-27 HIGH 8.8 CVE-2024-0880 A vulnerability was found in Qidianbang qdbcrm 1.1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file … Qdbcrm No fix yet Fix from $1,9502024-01-25 MEDIUM 5.3 CVE-2024-0624 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forg… Paid Memberships Pro after 2.12.7 Fix from $1,6002024-01-25 HIGH 8.8 CVE-2023-47024 Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vuln… Terminal Handler Mitigation only Fix from $1,9502024-01-20 HIGH 8.8 CVE-2023-47718 IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker … Maximo Application Suite 8.10.6+ Fix from $1,9502024-01-19 HIGH 8.3 CVE-2024-22424 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vu… Argo Cd 2.7.16 / 2.8.8+ Fix from $1,9502024-01-19 HIGH 8.8 CVE-2024-22601 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/scorerule_save Flycms Mitigation only Fix from $1,9502024-01-18 HIGH 8.8 CVE-2024-22603 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link Flycms No fix yet Fix from $1,9502024-01-18 HIGH 8.8 CVE-2024-22817 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte Flycms No fix yet Fix from $1,9502024-01-18 HIGH 8.8 CVE-2024-22818 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save Flycms No fix yet Fix from $1,9502024-01-18 HIGH 8.8 CVE-2024-22819 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update. Flycms No fix yet Fix from $1,9502024-01-18 HIGH 8.8 CVE-2024-22699 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save. Flycms No fix yet Fix from $1,9502024-01-18