Total
7170 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-40351 | 1 Jenkins | 1 Favorite View | 2024-11-21 | 4.3 Medium |
A cross-site request forgery (CSRF) vulnerability in Jenkins Favorite View Plugin 5.v77a_37f62782d and earlier allows attackers to add or remove views from another user's favorite views tab bar. | ||||
CVE-2023-40341 | 2 Jenkins, Redhat | 2 Blue Ocean, Ocp Tools | 2024-11-21 | 8.8 High |
A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specified URL, capturing GitHub credentials associated with an attacker-specified job. | ||||
CVE-2023-40337 | 2 Jenkins, Redhat | 2 Folders, Ocp Tools | 2024-11-21 | 4.3 Medium |
A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy a view inside a folder. | ||||
CVE-2023-40336 | 2 Jenkins, Redhat | 2 Folders, Ocp Tools | 2024-11-21 | 8.8 High |
A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy folders. | ||||
CVE-2023-40335 | 1 Cyberws | 1 Cleverwise Daily Quotes | 2024-11-21 | 7.1 High |
Cross-Site Request Forgery (CSRF) vulnerability in Jeremy O'Connell Cleverwise Daily Quotes allows Stored XSS.This issue affects Cleverwise Daily Quotes: from n/a through 3.2. | ||||
CVE-2023-40212 | 1 Multidots | 1 Product Attachment For Woocommerce | 2024-11-21 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versions. | ||||
CVE-2023-40210 | 1 Sean-barton | 1 Sb Child List | 2024-11-21 | 5.4 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Sean Barton (Tortoise IT) SB Child List plugin <= 4.5 versions. | ||||
CVE-2023-40202 | 1 Codemiq | 1 Wp Html Mail | 2024-11-21 | 5.4 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <= 3.4.1 versions. | ||||
CVE-2023-40201 | 1 Futuriowp | 1 Futurio Extra | 2024-11-21 | 6.5 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation of arbitrary plugin. | ||||
CVE-2023-40199 | 1 Crudlab | 1 Wp Like Button | 2024-11-21 | 5.4 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab WP Like Button plugin <= 1.7.0 versions. | ||||
CVE-2023-40198 | 1 Antsanchez | 1 Easy Cookie Law | 2024-11-21 | 5.4 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Antsanchez Easy Cookie Law plugin <= 3.1 versions. | ||||
CVE-2023-40172 | 1 Fobybus | 1 Social-media-skeleton | 2024-11-21 | 6.5 Medium |
Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. A Cross-site request forgery (CSRF) attack is a type of malicious attack whereby an attacker tricks a victim into performing an action on a website that they do not intend to do. This can be done by sending the victim a malicious link or by exploiting a vulnerability in the website. Prior to version 1.0.5 Social media skeleton did not properly restrict CSRF attacks. This has been addressed in version 1.0.5 and all users are advised to upgrade. There are no known workarounds for this vulnerability. | ||||
CVE-2023-40048 | 1 Progress | 1 Ws Ftp Server | 2024-11-21 | 6.8 Medium |
In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST transaction corresponding to a WS_FTP Server administrative function. | ||||
CVE-2023-40009 | 1 Thimpress | 1 Wp Pipes | 2024-11-21 | 5.4 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Pipes plugin <= 1.4.0 versions. | ||||
CVE-2023-40008 | 1 Webtechforce | 1 Simple Org Chart | 2024-11-21 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Gangesh Matta Simple Org Chart plugin <= 2.3.4 versions. | ||||
CVE-2023-3841 | 1 Nxfilter | 1 Nxfilter | 2024-11-21 | 4.3 Medium |
A vulnerability has been found in NxFilter 4.3.2.5 and classified as problematic. This vulnerability affects unknown code of the file user.jsp. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The identifier of this vulnerability is VDB-235192. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
CVE-2023-3627 | 1 Salesagility | 1 Suitecrm | 2024-11-21 | 8.8 High |
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1. | ||||
CVE-2023-3589 | 3 3ds, Dassault, Dassult | 5 Teamwork Cloud No Magic Release, Teamwork Cloud Enterprise Edition, Teamwork Cloud Standard Edition and 2 more | 2024-11-21 | 6.8 Medium |
A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server. | ||||
CVE-2023-3579 | 1 Hadsky | 1 Hadsky | 2024-11-21 | 4.3 Medium |
A vulnerability, which was classified as problematic, has been found in HadSky 7.11.8. Affected by this issue is some unknown functionality of the component User Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-233372. | ||||
CVE-2023-3414 | 1 Jenkins | 1 Servicenow Devops | 2024-11-21 | 6.1 Medium |
A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform. |