Filtered by CWE-352
Total 8116 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-36345 1 Metagauss 1 Download Plugin 2024-11-21 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download PluginĀ <= 2.0.4 versions.
CVE-2022-36312 1 Airspan 2 Airvelocity 1500, Airvelocity 1500 Firmware 2024-11-21 8.8 High
Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
CVE-2022-36225 1 Eyoucms 1 Eyoucms 2024-11-21 8.8 High
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
CVE-2022-36224 1 Xunruicms 1 Xunruicms 2024-11-21 8.8 High
XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-35656 1 Pega 1 Pega Platform 2024-11-21 4.5 Medium
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
CVE-2022-35286 2 Ibm, Linux 2 Security Verify Information Queue, Linux Kernel 2024-11-21 8.8 High
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814.
CVE-2022-35285 2 Ibm, Linux 2 Security Verify Information Queue, Linux Kernel 2024-11-21 8.8 High
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812.
CVE-2022-35228 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 8.8 High
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.
CVE-2022-34937 1 Yuba 1 U5cms 2024-11-21 8.8 High
Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers to execute arbitrary code.
CVE-2022-34817 1 Jenkins 1 Failed Job Deactivator 2024-11-21 4.3 Medium
A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows attackers to disable jobs.
CVE-2022-34815 1 Jenkins 1 Request Rename Or Delete 2024-11-21 4.3 Medium
A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows attackers to accept pending requests, thereby renaming or deleting jobs.
CVE-2022-34812 1 Jenkins 1 Xpath Configuration Viewer 2024-11-21 4.3 Medium
A cross-site request forgery (CSRF) vulnerability in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers to create and delete XPath expressions.
CVE-2022-34797 1 Jenkins 1 Deployment Dashboard 2024-11-21 4.3 Medium
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to connect to an attacker-specified HTTP URL using attacker-specified credentials.
CVE-2022-34792 1 Jenkins 1 Recipe 2024-11-21 8.0 High
A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.
CVE-2022-34789 1 Jenkins 1 Matrix Reloaded 2024-11-21 6.5 Medium
A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix builds.
CVE-2022-34780 1 Jenkins 1 Xebialabs Xl Release 2024-11-21 6.5 Medium
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2022-34367 1 Dell 1 Emc Data Protection Central 2024-11-21 5.4 Medium
Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unauthenticated attacker could potentially exploit this vulnerability, leading to processing of unintended server operations.
CVE-2022-34211 1 Jenkins 1 Vrealize Orchestrator 2024-11-21 6.5 Medium
A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST request to an attacker-specified URL.
CVE-2022-34209 1 Jenkins 1 Threadfix 2024-11-21 6.5 Medium
A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to connect to an attacker-specified URL.
CVE-2022-34207 1 Jenkins 1 Beaker Builder 2024-11-21 6.5 Medium
A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specified URL.