Total
9688 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-38934 | 2026-07-05 | N/A | 8.8 HIGH | ||
| Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php | |||||
| CVE-2025-60956 | 1 Endruntechnologies | 2 Sonoma D12, Sonoma D12 Firmware | 2026-07-05 | N/A | 8.0 HIGH |
| Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information. | |||||
| CVE-2026-36960 | 2026-07-05 | N/A | 8.8 HIGH | ||
| A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action. | |||||
| CVE-2026-36956 | 1 Dbitnet | 2 Dbit N300 T1 Pro, Dbit N300 T1 Pro Firmware | 2026-07-05 | N/A | 8.8 HIGH |
| A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints such as /api/setWlan. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action. | |||||
| CVE-2025-60535 | 2026-07-05 | N/A | 7.3 HIGH | ||
| A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request. | |||||
| CVE-2025-56400 | 1 Tuya | 3 Smartlife, Tuya, Tuya Smart | 2026-07-05 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices. This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms. | |||||
| CVE-2025-50847 | 1 Cs-cart | 1 Cs-cart | 2026-07-05 | N/A | 6.5 MEDIUM |
| Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP request. | |||||
| CVE-2025-50586 | 1 Daycloud | 1 Studentmanage | 2026-07-05 | N/A | 6.5 MEDIUM |
| StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF). | |||||
| CVE-2024-57523 | 1 Oretnom23 | 1 Packers And Movers Management System | 2026-07-05 | N/A | 4.5 MEDIUM |
| Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user. | |||||
| CVE-2024-48418 | 1 Edimax | 2 Br-6476ac, Br-6476ac Firmware | 2026-07-05 | N/A | 8.8 HIGH |
| In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands. | |||||
| CVE-2024-37774 | 1 Sunbirddcim | 1 Dctrack | 2026-07-05 | N/A | 8.0 HIGH |
| A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens. | |||||
| CVE-2018-14519 | 1 Getkirby | 1 Kirby | 2026-07-05 | N/A | 4.3 MEDIUM |
| An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page. | |||||
| CVE-2026-57766 | 2026-07-02 | N/A | 8.8 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions. | |||||
| CVE-2026-57759 | 2026-07-02 | N/A | 8.8 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. | |||||
| CVE-2026-57758 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions. | |||||
| CVE-2026-57747 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions. | |||||
| CVE-2026-13952 | 1 Google | 1 Chrome | 2026-07-02 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-13946 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-07-02 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-13944 | 2 Apple, Google | 2 Macos, Chrome | 2026-07-02 | N/A | 3.1 LOW |
| Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-57761 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions. | |||||
