Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-02-20 CVE-2022-48320 Cross-Site Request Forgery (CSRF) vulnerability in Checkmk 2.0.0/2.1.0
Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6.0 (EOL) allow an attacker to add new visual elements to multiple pages.
network
low complexity
checkmk CWE-352
4.3
2023-02-20 CVE-2023-25569 Cross-Site Request Forgery (CSRF) vulnerability in Apolloconfig Apollo
Apollo is a configuration management system.
network
low complexity
apolloconfig CWE-352
5.7
2023-02-17 CVE-2023-23899 Cross-Site Request Forgery (CSRF) vulnerability in Hasthemes Extensions for CF7
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Extensions For CF7 plugin <= 2.0.8 versions leads to arbitrary plugin activation.
network
low complexity
hasthemes CWE-352
4.3
2023-02-17 CVE-2023-24388 Cross-Site Request Forgery (CSRF) vulnerability in Wpdevart Booking Calendar
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete).
network
low complexity
wpdevart CWE-352
5.4
2023-02-15 CVE-2021-33396 Cross-Site Request Forgery (CSRF) vulnerability in Baijiacms Project Baijiacms 4.1.4
Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary account via index.php.
network
low complexity
baijiacms-project CWE-352
6.5
2023-02-15 CVE-2023-23465 Cross-Site Request Forgery (CSRF) vulnerability in Mediacp Media Control Panel 2.13.1
Media CP Media Control Panel latest version.
network
low complexity
mediacp CWE-352
8.8
2023-02-15 CVE-2023-23847 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Synopsys Coverity
A cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-352
3.5
2023-02-15 CVE-2023-25767 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Azure Credentials
A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an attacker-specified web server.
network
low complexity
jenkins CWE-352
8.8
2023-02-15 CVE-2022-29557 Cross-Site Request Forgery (CSRF) vulnerability in Relx Firco Compliance Link 3.7
LexisNexis Firco Compliance Link 3.7 allows CSRF.
network
low complexity
relx CWE-352
8.8
2023-02-14 CVE-2023-22942 Cross-Site Request Forgery (CSRF) vulnerability in Splunk
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a cross-site request forgery in the Splunk Secure Gateway (SSG) app in the ‘kvstore_client’ REST endpoint lets a potential attacker update SSG KV store collections using an HTTP GET request.
network
low complexity
splunk CWE-352
4.3