Show filters
1,722 Total Results
Displaying 91-100 of 1,722
Sort by:
Attacker Value
Unknown
CVE-2022-41971
Disclosure Date: December 01, 2022 (last updated February 24, 2025)
Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacker would be able to see videos on a call in a public conversation after being removed from that conversation, provided that they were removed while being in the call. Versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0 contain patches for the issue. No known workarounds are available.
0
Attacker Value
Unknown
CVE-2022-41297
Disclosure Date: December 01, 2022 (last updated February 24, 2025)
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.
0
Attacker Value
Unknown
CVE-2022-40489
Disclosure Date: December 01, 2022 (last updated February 24, 2025)
ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users.
0
Attacker Value
Unknown
CVE-2022-26366
Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress.
0
Attacker Value
Unknown
CVE-2022-43481
Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Coupons for WooCommerce Coupons plugin <= 4.5 on WordPress leading to notice dismissal.
0
Attacker Value
Unknown
CVE-2022-41413
Disclosure Date: November 30, 2022 (last updated February 24, 2025)
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function.
0
Attacker Value
Unknown
CVE-2022-3898
Disclosure Date: November 29, 2022 (last updated February 24, 2025)
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce validation on various functions including the affiliates_menu method. This makes it possible for unauthenticated attackers to delete affiliate records, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-3747
Disclosure Date: November 29, 2022 (last updated February 24, 2025)
The Becustom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.2. This is due to missing nonce validation when saving the plugin's settings. This makes it possible for unauthenticated attackers to update the plugin's settings like betheme_url_slug, replaced_theme_author, and betheme_label to name a few, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-44937
Disclosure Date: November 28, 2022 (last updated February 24, 2025)
Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module.
0
Attacker Value
Unknown
CVE-2022-34654
Disclosure Date: November 28, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notification E-mails plugin <= 1.8.2 on WordPress.
0