Total
7863 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-41249 | 1 Jenkins | 1 Scm Httpclient | 2025-05-27 | N/A | 8.8 HIGH |
A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |||||
CVE-2022-23685 | 1 Arubanetworks | 1 Clearpass Policy Manager | 2025-05-27 | N/A | 8.8 HIGH |
A vulnerability in the ClearPass Policy Manager web-based management interface exists which exposes some endpoints to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against these endpoints if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address this security vulnerability. | |||||
CVE-2024-46485 | 1 Timgreen | 1 Dingfanzu Cms | 2025-05-27 | N/A | 6.3 MEDIUM |
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate | |||||
CVE-2024-46600 | 1 Timgreen | 1 Dingfanzu Cms | 2025-05-27 | N/A | 4.7 MEDIUM |
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31 | |||||
CVE-2023-50900 | 1 Averta | 1 Master Slider | 2025-05-27 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.10. | |||||
CVE-2024-6490 | 1 Averta | 1 Master Slider | 2025-05-27 | N/A | 6.5 MEDIUM |
During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10. | |||||
CVE-2024-31374 | 1 Apppresser | 1 Apppresser | 2025-05-27 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0. | |||||
CVE-2024-31268 | 1 Apppresser | 1 Apppresser | 2025-05-27 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0. | |||||
CVE-2025-44186 | 1 Mayurik | 1 Best Employee Management System | 2025-05-27 | N/A | 5.4 MEDIUM |
SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page. | |||||
CVE-2024-27967 | 1 Dsgvo-for-wp | 1 Dsgvo All In One For Wp | 2025-05-27 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Michael Leithold DSGVO All in one for WP.This issue affects DSGVO All in one for WP: from n/a through 4.3. | |||||
CVE-2025-24223 | 1 Apple | 7 Ipados, Iphone Os, Macos and 4 more | 2025-05-27 | N/A | 8.0 HIGH |
The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption. | |||||
CVE-2025-31205 | 1 Apple | 7 Ipados, Iphone Os, Macos and 4 more | 2025-05-27 | N/A | 6.5 MEDIUM |
The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin. | |||||
CVE-2025-1926 | 1 Pagelayer | 1 Pagelayer | 2025-05-26 | N/A | 4.3 MEDIUM |
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the pagelayer_save_post function. This makes it possible for unauthenticated attackers to modify post contents via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2024-13356 | 1 Dsgvo-for-wp | 1 Dsgvo All In One For Wp | 2025-05-23 | N/A | 6.5 MEDIUM |
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This makes it possible for unauthenticated attackers to delete admin user accounts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2025-0522 | 1 Tommietott | 1 Likebot | 2025-05-23 | N/A | 4.7 MEDIUM |
The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |||||
CVE-2025-46458 | 2025-05-23 | N/A | 8.2 HIGH | ||
Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan allows SQL Injection. This issue affects occupancyplan: from n/a through 1.0.3.0. | |||||
CVE-2024-54851 | 1 Sismics | 1 Teedy | 2025-05-23 | N/A | 8.8 HIGH |
Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection. | |||||
CVE-2023-50768 | 1 Jenkins | 1 Nexus Platform | 2025-05-22 | N/A | 8.8 HIGH |
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |||||
CVE-2021-37198 | 1 Siemens | 1 Comos | 2025-05-22 | 5.1 MEDIUM | 8.8 HIGH |
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS uses a flawed implementation of CSRF prevention. An attacker could exploit this vulnerability to perform cross-site request forgery attacks. | |||||
CVE-2024-48311 | 1 Piwigo | 1 Piwigo | 2025-05-22 | N/A | 8.8 HIGH |
Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function. |