Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-22568 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del. Flycms No fix yet Fix from $1,9502024-01-18 HIGH 8.8 CVE-2024-22591 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save. Flycms No fix yet Fix from $1,9502024-01-18 HIGH 8.8 CVE-2024-22592 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update Flycms No fix yet Fix from $1,9502024-01-18 HIGH 8.8 CVE-2024-22593 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save Flycms No fix yet Fix from $1,9502024-01-18 HIGH 8.8 CVE-2024-22416 pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. Since t… Pyload Ng 0.5.0b3.dev78+ Fix from $1,9502024-01-18 HIGH 8.8 CVE-2024-22715 Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php. Stupid Simple Cms after 1.2.4 Fix from $1,9502024-01-17 HIGH 8.8 CVE-2022-41990 Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8. Cardoza 3d Tag Cloud after 3.8 Fix from $1,9502024-01-17 MEDIUM 6.5 CVE-2023-5006 The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker t… Wp Discord Invite 2.5.1+ Fix from $1,6002024-01-17 MEDIUM 6.1 CVE-2024-20940 Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Create, Update, Authoring Flow). Supported versions … Knowledge Management after 12.2.13 Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2024-20942 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: LOV). Supported versions that are a… Complex Maintenance\, Repair\, And Overhaul Patch available Fix from $1,6002024-01-16 MEDIUM 5.4 CVE-2024-20944 Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 1… Isupport after 12.2.13 Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2024-20934 Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are aff… Installed Base after 12.2.13 Fix from $1,6002024-01-16 MEDIUM 5.4 CVE-2023-7083 The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could … Voting Record after 2.0 Fix from $1,6002024-01-16 HIGH 8.1 CVE-2022-3899 The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plug… 3dprint 3.5.6.9+ Fix from $1,9502024-01-16 MEDIUM 6.5 CVE-2023-0824 The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as esc… Userplus after 2.0 Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2021-24870 The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and es… Wp Fastest Cache 0.9.5+ Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2022-1617 The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as es… Wp Invoice after 4.3.1 Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2022-1618 The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as esc… Coru Lfmember after 1.0.2 Fix from $1,6002024-01-16 HIGH 8.0 CVE-2024-0555 A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user int… Wic1200 Firmware Mitigation only Fix from $1,9502024-01-16 HIGH 8.8 CVE-2024-0522 A vulnerability was found in Allegro RomPager 4.01. It has been classified as problematic. Affected is an unknown function of the file usertable.htm?… Rompager Mitigation only Fix from $1,9502024-01-14 HIGH 8.8 CVE-2023-51063 QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability … Archive Storage Manager No fix yet Fix from $1,9502024-01-13 HIGH 8.8 CVE-2023-51949 Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller Verydows No fix yet Fix from $1,9502024-01-12 MEDIUM 5.4 CVE-2023-4247 The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incor… Givewp after 2.33.3 Fix from $1,6002024-01-11 HIGH 8.8 CVE-2023-5448 The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This… Wp Register Profile With Shortcode after 3.5.9 Fix from $1,9502024-01-11 MEDIUM 6.5 CVE-2023-5455 A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to tri… Fedora Mitigation only Fix from $1,6002024-01-10 HIGH 8.1 CVE-2023-48258 The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session. Nexo Os after 1500-sp2 Fix from $1,9502024-01-10 MEDIUM 5.4 CVE-2023-50932 An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S… S Notify 4.0.2+ Fix from $1,6002024-01-09 MEDIUM 5.4 CVE-2023-50931 An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/… S Notify 2.0.1+ Fix from $1,6002024-01-09 HIGH 7.1 CVE-2023-50930 An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notif… S Notify 4.0.2+ Fix from $1,9502024-01-09 MEDIUM 5.4 CVE-2023-6788 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8… Metform Elementor Contact Form Builder after 3.8.1 Fix from $1,6002024-01-09