Total
6289 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-34209 | 1 Jenkins | 1 Threadfix | 2024-08-03 | 6.5 Medium |
A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to connect to an attacker-specified URL. | ||||
CVE-2022-34205 | 1 Jenkins | 1 Jianliao Notification | 2024-08-03 | 6.5 Medium |
A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests to an attacker-specified URL. | ||||
CVE-2022-34211 | 1 Jenkins | 1 Vrealize Orchestrator | 2024-08-03 | 6.5 Medium |
A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST request to an attacker-specified URL. | ||||
CVE-2022-34200 | 1 Jenkins | 1 Convertigo Mobile Platform | 2024-08-03 | 8.8 High |
A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an attacker-specified URL. | ||||
CVE-2022-34158 | 1 Apache | 1 Jspwiki | 2024-08-03 | 8.8 High |
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page. | ||||
CVE-2022-34207 | 1 Jenkins | 1 Beaker Builder | 2024-08-03 | 6.5 Medium |
A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specified URL. | ||||
CVE-2022-34203 | 1 Jenkins | 1 Easyqa | 2024-08-03 | 8.8 High |
A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP server. | ||||
CVE-2022-34134 | 1 Jorani | 1 Jorani | 2024-08-03 | 8.8 High |
Benjamin BALET Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php. | ||||
CVE-2022-34020 | 1 Resiot | 1 Iot Platform And Lorawan Network Server | 2024-08-03 | 8.8 High |
Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add new admin users to the platform or other unspecified impacts. | ||||
CVE-2022-33121 | 1 1234n | 1 Minicms | 2024-08-03 | 8.1 High |
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link. | ||||
CVE-2022-32555 | 1 Unisys | 1 Data Exchange Management Studio | 2024-08-03 | 8.8 High |
Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery attack could occur. | ||||
CVE-2022-32516 | 1 Schneider-electric | 2 Conext Combox, Conext Combox Firmware | 2024-08-03 | 7.5 High |
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affected Products: Conext™ ComBox (All Versions) | ||||
CVE-2022-32320 | 2 Ferdium, Getferdi | 2 Ferdium, Ferdi | 2024-08-03 | 8.8 High |
A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file such as a settings/preferences file. | ||||
CVE-2022-31886 | 1 Marvalglobal | 1 Marval Msm | 2024-08-03 | 6.5 Medium |
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form. | ||||
CVE-2022-31294 | 1 Online Discussion Forum Site Project | 1 Online Discussion Forum Site | 2024-08-03 | 6.5 Medium |
An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts. | ||||
CVE-2022-31000 | 1 Nebulab | 1 Solidus | 2024-08-03 | 2.3 Low |
solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16 contain a cross-site request forgery (CSRF) vulnerability. The vulnerability allows attackers to change the state of an order's adjustments if they hold its number, and the execution happens on a store administrator's computer. Users should upgrade to solidus_backend 3.1.6, 3.0.6, or 2.11.16 to receive a patch. | ||||
CVE-2022-30972 | 1 Jenkins | 1 Storage Configs | 2024-08-03 | 8.8 High |
A cross-site request forgery (CSRF) vulnerability in Jenkins Storable Configs Plugin 1.0 and earlier allows attackers to have Jenkins parse a local XML file (e.g., archived artifacts) that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery. | ||||
CVE-2022-30958 | 1 Jenkins | 1 Ssh | 2024-08-03 | 8.8 High |
A cross-site request forgery (CSRF) vulnerability in Jenkins SSH Plugin 2.6.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | ||||
CVE-2022-30969 | 1 Jenkins | 1 Autocomplete Parameter | 2024-08-03 | 8.8 High |
A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code without sandbox protection if the victim is an administrator. | ||||
CVE-2022-30953 | 2 Jenkins, Redhat | 3 Blue Ocean, Ocp Tools, Openshift | 2024-08-03 | 6.5 Medium |
A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specified HTTP server. |