Show filters
1,591 Total Results
Displaying 71-80 of 1,591
Sort by:
Attacker Value
Unknown
CVE-2022-32175
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules.
0
Attacker Value
Unknown
CVE-2022-40180
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). A Cross-Site Request Forgery exists in the “Import Files“ functionality of the “Operation” web application due to the missing validation of anti-CSRF tokens or other origin checks. A remote unauthenticated attacker can upload and enable permanent arbitrary JavaScript code into the device just by convincing a victim to visit a specifically crafted webpage while logged-in to the device web application.
0
Attacker Value
Unknown
CVE-2022-40179
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). A Cross-Site Request Forgery exists in endpoints of the “Operation” web application that interpret and execute Axon language queries, due to the missing validation of anti-CSRF tokens or other origin checks. By convincing a victim to click on a malicious link or visit a specifically crafted webpage while logged-in to the device web application, a remote unauthenticated attacker can execute arbitrary Axon queries against the device.
0
Attacker Value
Unknown
CVE-2022-36360
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load firmware updates without checking the authenticity. Furthermore the integrity of the unencrypted firmware is only verified by a non-cryptographic method. This could allow an attacker to manipulate a firmware update and flash it to the device.
0
Attacker Value
Unknown
CVE-2022-3208
Disclosure Date: October 10, 2022 (last updated February 24, 2025)
The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new page and change it's content via a CSRF attack.
0
Attacker Value
Unknown
CVE-2022-3154
Disclosure Date: October 10, 2022 (last updated February 24, 2025)
The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin's license
0
Attacker Value
Unknown
CVE-2022-2350
Disclosure Date: October 10, 2022 (last updated February 24, 2025)
The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.
0
Attacker Value
Unknown
CVE-2022-2986
Disclosure Date: October 06, 2022 (last updated February 24, 2025)
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
0
Attacker Value
Unknown
CVE-2022-2783
Disclosure Date: October 06, 2022 (last updated February 24, 2025)
In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token
0
Attacker Value
Unknown
CVE-2022-22493
Disclosure Date: October 04, 2022 (last updated February 24, 2025)
IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449.
0