Vulnerabilities (CVE)

Filtered by CWE-352
Total 5841 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3414 1 Jenkins 1 Servicenow Devops 2023-08-01 N/A 6.5 MEDIUM
A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.
CVE-2023-39156 1 Jenkins 1 Bazaar 2023-08-01 N/A 5.3 MEDIUM
A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete previously created Bazaar SCM tags.
CVE-2023-36162 1 Zzcms 1 Zzcms 2023-08-01 N/A 8.8 HIGH
Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in adminlist.php.
CVE-2023-28023 1 Hcltech 1 Bigfix Webui 2023-08-01 N/A 6.5 MEDIUM
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 
CVE-2023-39153 1 Jenkins 1 Gitlab Authentication 2023-07-31 N/A 5.4 MEDIUM
A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.
CVE-2023-25482 1 Keetrax 1 Wp Tiles 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Mike Martel WP Tiles plugin <= 1.1.2 versions.
CVE-2023-25475 1 Smart Youtube Pro Project 1 Smart Youtube Pro 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Vladimir Prelovac Smart YouTube PRO plugin <= 4.3 versions.
CVE-2023-32761 1 Archerirm 1 Archer 2023-07-27 N/A 8.0 HIGH
Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.
CVE-2023-25473 1 Flickr Justified Gallery Project 1 Flickr Justified Gallery 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Miro Mannino Flickr Justified Gallery plugin <= 3.5 versions.
CVE-2022-45828 1 Nootheme 1 Noo Timetable 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in NooTheme Noo Timetable plugin <= 2.1.3 versions.
CVE-2022-46857 1 Sitealert 1 Sitealert 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in SiteAlert plugin <= 1.9.7 versions.
CVE-2023-36511 1 Woocommerce 1 Woocommerce Order Barcodes 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Order Barcodes plugin <= 1.6.4 versions.
CVE-2023-37968 1 Faboba 1 Falang 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Faboba Falang multilanguage for WordPress plugin <= 1.3.39 versions.
CVE-2023-36514 1 Woocommerce 1 Shipping Multiple Addresses 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions.
CVE-2023-36513 1 Woocommerce 1 Automatewoo 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions.
CVE-2023-37985 1 Fivestarplugins 1 Five Star Restaurant Menu 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions.
CVE-2023-37974 1 Wp Social Autoconnect Project 1 Wp Social Autoconnect 2023-07-27 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Justin Klein WP Social AutoConnect plugin <= 4.6.1 versions.
CVE-2023-38349 1 Pnp4nagios 1 Pnp4nagios 2023-07-26 N/A 8.8 HIGH
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
CVE-2023-31216 1 Ultimatemember 1 Ultimate Member 2023-07-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.
CVE-2023-37650 1 Agentejo 1 Cockpit 2023-07-26 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.