Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-07-26 CVE-2023-39156 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Bazaar
A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete previously created Bazaar SCM tags.
network
low complexity
jenkins CWE-352
5.3
2023-07-24 CVE-2022-30280 Cross-Site Request Forgery (CSRF) vulnerability in Nokia Netact 22.0.0.62
/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF.
network
low complexity
nokia CWE-352
8.8
2023-07-21 CVE-2023-32625 Cross-Site Request Forgery (CSRF) vulnerability in Sakura TS Webfonts
Cross-site request forgery (CSRF) vulnerability in TS Webfonts for SAKURA 3.1.2 and earlier allows a remote unauthenticated attacker to hijack the authentication of a user and to change settings by having a user view a malicious page.
network
low complexity
sakura CWE-352
4.3
2023-07-20 CVE-2023-37650 Cross-Site Request Forgery (CSRF) vulnerability in Agentejo Cockpit
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
network
low complexity
agentejo CWE-352
8.8
2023-07-18 CVE-2023-28023 Cross-Site Request Forgery (CSRF) vulnerability in Hcltech Bigfix Webui 14/20/44
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 
network
low complexity
hcltech CWE-352
6.5
2023-07-18 CVE-2022-45828 Cross-Site Request Forgery (CSRF) vulnerability in Nootheme NOO Timetable 2.1.3
Cross-Site Request Forgery (CSRF) vulnerability in NooTheme Noo Timetable plugin <= 2.1.3 versions.
network
low complexity
nootheme CWE-352
8.8
2023-07-17 CVE-2022-38062 Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Theme
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Theme plugin <= 1.0.9 versions.
network
low complexity
metagauss CWE-352
8.8
2023-07-17 CVE-2023-35089 Cross-Site Request Forgery (CSRF) vulnerability in Really-Simple-Plugins Recipe Maker for Your Food Blog From ZIP Recipes
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions.
network
low complexity
really-simple-plugins CWE-352
8.8
2023-07-15 CVE-2023-38349 Cross-Site Request Forgery (CSRF) vulnerability in Pnp4Nagios 0.6.26
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller.
network
low complexity
pnp4nagios CWE-352
8.8
2023-07-14 CVE-2023-32761 Cross-Site Request Forgery (CSRF) vulnerability in Archerirm Archer
Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.
network
low complexity
archerirm CWE-352
8.0