Total
9704 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-5185 | 2026-06-17 | N/A | 7.3 HIGH | ||
| The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result in the application becoming compromised, leading to unauthorized entries or data poisoning attacks, which are delivered by a CSRF vulnerability due to the absence of a secure session management implementation and weak CORS policies weakness. An attacker can direct a user to a malicious webpage that exploits a CSRF vulnerability within the EmbedAI application. By leveraging this CSRF vulnerability, the attacker can deceive the user into inadvertently uploading and integrating incorrect data into the application’s language model. | |||||
| CVE-2024-5167 | 1 Cminds | 1 Cm E-mail Blacklist | 2026-06-17 | N/A | 8.1 HIGH |
| The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist menu via a CSRF attack | |||||
| CVE-2024-5155 | 1 Ravster | 1 Inquiry Cart | 2026-06-17 | N/A | 6.1 MEDIUM |
| The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |||||
| CVE-2024-5097 | 1 Argie | 1 Simple Inventory System | 2026-06-17 | 5.0 MEDIUM | 4.3 MEDIUM |
| A vulnerability, which was classified as problematic, was found in SourceCodester Simple Inventory System 1.0. Affected is an unknown function of the file /tableedit.php#page=editprice. The manipulation of the argument itemnumber leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265080. | |||||
| CVE-2024-5081 | 1 Tipsandtricks-hq | 1 Wp Emember | 2026-06-17 | N/A | 6.1 MEDIUM |
| The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |||||
| CVE-2024-5077 | 1 Tipsandtricks-hq | 1 Wp Emember | 2026-06-17 | N/A | 6.8 MEDIUM |
| The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |||||
| CVE-2024-5076 | 1 Tipsandtricks-hq | 1 Wp Emember | 2026-06-17 | N/A | 8.8 HIGH |
| The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | |||||
| CVE-2024-5034 | 1 Toolstack | 1 Sully | 2026-06-17 | N/A | 8.8 HIGH |
| The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | |||||
| CVE-2024-5033 | 1 Toolstack | 1 Sully | 2026-06-17 | N/A | 5.9 MEDIUM |
| The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |||||
| CVE-2024-5030 | 1 Cminds | 1 Cm Table Of Contents | 2026-06-17 | N/A | 3.8 LOW |
| The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |||||
| CVE-2024-5029 | 1 Cminds | 1 Cm Table Of Contents | 2026-06-17 | N/A | 4.8 MEDIUM |
| The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |||||
| CVE-2024-5028 | 1 Cminds | 1 Cm Search And Replace | 2026-06-17 | N/A | 6.5 MEDIUM |
| The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | |||||
| CVE-2024-5003 | 1 Jankarres | 1 Wp Stacker | 2026-06-17 | N/A | 5.4 MEDIUM |
| The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |||||
| CVE-2024-57611 | 1 07fly | 1 07flycms | 2026-06-17 | N/A | 3.5 LOW |
| 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId. | |||||
| CVE-2024-57429 | 1 Phpjabbers | 1 Cinema Booking System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request. | |||||
| CVE-2024-57373 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to account modifications or data compromise. | |||||
| CVE-2024-57161 | 1 07fly | 1 Customer Relationship Management | 2026-06-17 | N/A | 4.3 MEDIUM |
| 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html | |||||
| CVE-2024-57160 | 1 07fly | 1 Customer Relationship Management | 2026-06-17 | N/A | 4.3 MEDIUM |
| 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html. | |||||
| CVE-2024-57159 | 1 07fly | 1 07flycms | 2026-06-17 | N/A | 3.5 LOW |
| 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html. | |||||
| CVE-2024-56924 | 1 Codeastro | 1 Internet Banking System | 2026-06-17 | N/A | 7.3 HIGH |
| A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts. | |||||
