Total
6068 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-27629 | 1 Videowhisper | 1 Micropayments | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership' versions prior to 1.9.6 allows a remote unauthenticated attacker to hijack the authentication of an administrator and perform unintended operation via unspecified vectors. | |||||
CVE-2021-32929 | 1 Uffizio | 1 Gps Tracker | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user. | |||||
CVE-2022-31886 | 1 Marvalglobal | 1 Marval Msm | 2024-02-28 | 4.3 MEDIUM | 6.5 MEDIUM |
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form. | |||||
CVE-2022-34200 | 1 Jenkins | 1 Convertigo Mobile Platform | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an attacker-specified URL. | |||||
CVE-2022-1764 | 1 Wp-chgfontsize Project | 1 Wp-chgfontsize | 2024-02-28 | 3.5 LOW | 5.4 MEDIUM |
The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping | |||||
CVE-2022-29453 | 1 Ayecode | 1 Api Key For Google Maps | 2024-02-28 | 4.3 MEDIUM | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update. | |||||
CVE-2022-30953 | 1 Jenkins | 1 Blue Ocean | 2024-02-28 | 4.3 MEDIUM | 6.5 MEDIUM |
A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specified HTTP server. | |||||
CVE-2022-28108 | 1 Selenium | 1 Selenium Grid | 2024-02-28 | 9.3 HIGH | 8.8 HIGH |
Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain. | |||||
CVE-2022-27340 | 1 Mingsoft | 1 Mcms | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data. | |||||
CVE-2022-29430 | 1 Png To Jpg Project | 1 Png To Jpg | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin <= 4.0 at WordPress via Cross-Site Request Forgery (CSRF). Vulnerable parameter &jpg_quality. | |||||
CVE-2022-1779 | 1 Auto Delete Posts Project | 1 Auto Delete Posts | 2024-02-28 | 5.8 MEDIUM | 8.1 HIGH |
The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once. | |||||
CVE-2022-30327 | 1 Trendnet | 2 Tew-831dr, Tew-831dr Firmware | 2024-02-28 | 4.3 MEDIUM | 6.5 MEDIUM |
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The web interface is vulnerable to CSRF. An attacker can change the pre-shared key of the Wi-Fi router if the interface's IP address is known. | |||||
CVE-2022-29429 | 1 Code Snippets Extended Project | 1 Code Snippets Extended | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery. | |||||
CVE-2022-23975 | 1 Accesspressthemes | 1 Access Demo Importer | 2024-02-28 | 4.3 MEDIUM | 6.5 MEDIUM |
Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin. | |||||
CVE-2022-34203 | 1 Jenkins | 1 Easyqa | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP server. | |||||
CVE-2022-1758 | 1 Genki Pre-publish Reminder Project | 1 Genki Pre-publish Reminder | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the plugin settings. | |||||
CVE-2022-0916 | 1 Logitech | 1 Options | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations. | |||||
CVE-2022-1900 | 1 Copify | 1 Copify | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. This is due to missing nonce validation on the CopifySettings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2022-25778 | 1 Secomea | 8 Gatemanager 4250, Gatemanager 4250 Firmware, Gatemanager 4260 and 5 more | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session. | |||||
CVE-2022-1624 | 1 Latest Tweets Widget Project | 1 Latest Tweets Widget | 2024-02-28 | 4.3 MEDIUM | 6.5 MEDIUM |
The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |