Vulnerabilities (CVE)

Filtered by CWE-352
Total 9688 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-38934 2026-07-05 N/A 8.8 HIGH
Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php
CVE-2025-60956 1 Endruntechnologies 2 Sonoma D12, Sonoma D12 Firmware 2026-07-05 N/A 8.0 HIGH
Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.
CVE-2026-36960 2026-07-05 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.
CVE-2026-36956 1 Dbitnet 2 Dbit N300 T1 Pro, Dbit N300 T1 Pro Firmware 2026-07-05 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints such as /api/setWlan. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.
CVE-2025-60535 2026-07-05 N/A 7.3 HIGH
A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request.
CVE-2025-56400 1 Tuya 3 Smartlife, Tuya, Tuya Smart 2026-07-05 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices. This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms.
CVE-2025-50847 1 Cs-cart 1 Cs-cart 2026-07-05 N/A 6.5 MEDIUM
Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP request.
CVE-2025-50586 1 Daycloud 1 Studentmanage 2026-07-05 N/A 6.5 MEDIUM
StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).
CVE-2024-57523 1 Oretnom23 1 Packers And Movers Management System 2026-07-05 N/A 4.5 MEDIUM
Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.
CVE-2024-48418 1 Edimax 2 Br-6476ac, Br-6476ac Firmware 2026-07-05 N/A 8.8 HIGH
In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.
CVE-2024-37774 1 Sunbirddcim 1 Dctrack 2026-07-05 N/A 8.0 HIGH
A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.
CVE-2018-14519 1 Getkirby 1 Kirby 2026-07-05 N/A 4.3 MEDIUM
An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page.
CVE-2026-57766 2026-07-02 N/A 8.8 HIGH
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.
CVE-2026-57759 2026-07-02 N/A 8.8 HIGH
Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
CVE-2026-57758 2026-07-02 N/A 7.1 HIGH
Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.
CVE-2026-57747 2026-07-02 N/A 6.5 MEDIUM
Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.
CVE-2026-13952 1 Google 1 Chrome 2026-07-02 N/A 4.3 MEDIUM
Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-13946 2 Apple, Google 2 Iphone Os, Chrome 2026-07-02 N/A 4.3 MEDIUM
Inappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-13944 2 Apple, Google 2 Macos, Chrome 2026-07-02 N/A 3.1 LOW
Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-57761 2026-07-02 N/A 7.1 HIGH
Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.