Total
7786 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-43147 | 1 Phpjabbers | 1 Limo Booking Software | 2024-11-21 | N/A | 8.8 HIGH |
PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI. | |||||
CVE-2023-43118 | 1 Extremenetworks | 1 Exos | 2024-11-21 | N/A | 8.8 HIGH |
Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 32.5.1.5 allows attackers to run arbitrary code and cause other unspecified impacts via /jsonrpc API. | |||||
CVE-2023-42435 | 1 Dexma | 1 Dexgate | 2024-11-21 | N/A | 5.5 MEDIUM |
The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to perform actions with the permissions of a victim user. | |||||
CVE-2023-42323 | 1 Mnbvcxz131421 | 1 Douhaocms | 2024-11-21 | N/A | 8.8 HIGH |
Cross Site Request Forgery (CSRF) vulnerability in DouHaocms v.3.3 allows a remote attacker to execute arbitrary code via the adminAction.class.php file. | |||||
CVE-2023-42321 | 1 Icmsdev | 1 Icms | 2024-11-21 | N/A | 8.8 HIGH |
Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files. | |||||
CVE-2023-42270 | 1 Grocy Project | 1 Grocy | 2024-11-21 | N/A | 8.8 HIGH |
Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF). | |||||
CVE-2023-42188 | 1 Macwk | 1 Icecms | 2024-11-21 | N/A | 6.5 MEDIUM |
IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF). | |||||
CVE-2023-42027 | 4 Hp, Ibm, Linux and 1 more | 6 Hp-ux, Aix, Cics Tx and 3 more | 2024-11-21 | N/A | 4.3 MEDIUM |
IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 266057. | |||||
CVE-2023-41950 | 1 Laposta | 1 Laposta Signup Basic | 2024-11-21 | N/A | 5.4 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Laposta - Roel Bousardt Laposta Signup Basic plugin <= 1.4.1 versions. | |||||
CVE-2023-41946 | 1 Jenkins | 1 Frugal Testing | 2024-11-21 | N/A | 3.5 LOW |
A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names from Frugal Testing, if a valid credential corresponds to the attacker-specified username. | |||||
CVE-2023-41942 | 1 Jenkins | 1 Aws Codecommit Trigger | 2024-11-21 | N/A | 4.3 MEDIUM |
A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers to clear the SQS queue. | |||||
CVE-2023-41938 | 1 Jenkins | 1 Ivy | 2024-11-21 | N/A | 6.5 MEDIUM |
A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and earlier allows attackers to delete disabled modules. | |||||
CVE-2023-41876 | 1 Wp Gallery Metabox Project | 1 Wp Gallery Metabox | 2024-11-21 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Hardik Kalathiya WP Gallery Metabox plugin <= 1.0.0 versions. | |||||
CVE-2023-41864 | 2024-11-21 | N/A | 4.3 MEDIUM | ||
Cross-Site Request Forgery (CSRF) vulnerability in Pepro Dev. Group PeproDev CF7 Database.This issue affects PeproDev CF7 Database: from n/a through 1.8.0. | |||||
CVE-2023-41858 | 1 Tychesoftwares | 1 Order Delivery Date For Woocommerce | 2024-11-21 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions. | |||||
CVE-2023-41854 | 1 Wpcentral | 1 Wpcentral | 2024-11-21 | N/A | 5.4 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Ltd. WpCentral plugin <= 1.5.7 versions. | |||||
CVE-2023-41853 | 1 Wpicalavailability | 1 Wp Ical Availability | 2024-11-21 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in WP iCal Availability plugin <= 1.0.3 versions. | |||||
CVE-2023-41852 | 1 Mailmunch | 1 Mailmunch | 2024-11-21 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailMunch – Grow your Email List plugin <= 3.1.2 versions. | |||||
CVE-2023-41851 | 1 Dotsquares | 1 Wp Custom Post Template | 2024-11-21 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Dotsquares WP Custom Post Template <= 1.0 versions. | |||||
CVE-2023-41850 | 1 Sparro | 1 Outbound Link Manager | 2024-11-21 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Morris Bryant, Ruben Sargsyan Outbound Link Manager plugin <= 1.2 versions. |