Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-352 Clear
ID Title
CVE-2026-74867 Cross-Site Request Forgery (CSRF) in CVE-2026-74867 (CVE-2026-74867)
vulnerability in CVE-2026-74867 (CVE-2026-74867). Risk of unauthorized operations or information disclosure.
CVE-2026-17608 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-17608)
vulnerability in wordpress (CVE-2026-17608). Data can be tampered with by attackers.
CVE-2026-15384 Authentication Bypass in wordpress (CVE-2026-15384)
authentication bypass in wordpress (CVE-2026-15384). Data can be tampered with by attackers.
CVE-2026-18165 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-18165)
vulnerability in csrf (CVE-2026-18165). Risk of unauthorized operations or information disclosure.
CVE-2026-67366 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-67366)
vulnerability in csrf (CVE-2026-67366). Risk of unauthorized operations or information disclosure.
CVE-2026-73847 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73847)
vulnerability in csrf (CVE-2026-73847). Confidential information can be exposed externally.
CVE-2026-57469 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-57469)
vulnerability in csrf (CVE-2026-57469). Risk of unauthorized operations or information disclosure.
CVE-2025-10308 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2025-10308)
vulnerability in wordpress (CVE-2025-10308). Risk of unauthorized operations or information disclosure.
CVE-2026-19786 Cross-Site Request Forgery (CSRF) in CVE-2026-19786 (CVE-2026-19786)
vulnerability in CVE-2026-19786 (CVE-2026-19786). Risk of unauthorized operations or information disclosure.
CVE-2026-72849 Cross-Site Request Forgery (CSRF) in CVE-2026-72849 (CVE-2026-72849)
vulnerability in CVE-2026-72849 (CVE-2026-72849). Confidential information can be exposed externally.
CVE-2026-72658 Cross-Site Request Forgery (CSRF) in privilege-escalation (CVE-2026-72658)
vulnerability in privilege-escalation (CVE-2026-72658). Confidential information can be exposed externally.
CVE-2026-17069 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-17069)
vulnerability in csrf (CVE-2026-17069). Confidential information can be exposed externally.
CVE-2026-13365 Cross-Site Request Forgery (CSRF) in ibm (CVE-2026-13365)
vulnerability in ibm (CVE-2026-13365). Data can be tampered with by attackers.
CVE-2026-73481 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73481)
vulnerability in csrf (CVE-2026-73481). Risk of unauthorized operations or information disclosure.
CVE-2026-73482 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73482)
vulnerability in csrf (CVE-2026-73482). Data can be tampered with by attackers.
CVE-2026-73575 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73575)
vulnerability in csrf (CVE-2026-73575). Risk of unauthorized operations or information disclosure.
CVE-2026-67990 Cross-Site Request Forgery (CSRF) in rails (CVE-2026-67990)
vulnerability in rails (CVE-2026-67990). Risk of unauthorized operations or information disclosure.
CVE-2025-62318 Cross-Site Request Forgery (CSRF) in CVE-2025-62318 (CVE-2025-62318)
vulnerability in CVE-2025-62318 (CVE-2025-62318). Risk of unauthorized operations or information disclosure.
CVE-2026-19088 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-19088)
vulnerability in wordpress (CVE-2026-19088). Risk of unauthorized operations or information disclosure.
CVE-2026-48551 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-48551)
vulnerability in csrf (CVE-2026-48551). Data can be tampered with by attackers.
CVE-2026-73292 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73292)
vulnerability in csrf (CVE-2026-73292). Confidential information can be exposed externally.
CVE-2026-73222 Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
CVE-2026-73162 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73162)
vulnerability in csrf (CVE-2026-73162). Risk of unauthorized operations or information disclosure.
CVE-2026-19418 Vulnerability in CVE-2026-19418 (CVE-2026-19418)
vulnerability in CVE-2026-19418 (CVE-2026-19418). Risk of unauthorized operations or information disclosure.
CVE-2026-66775 Cross-Site Request Forgery (CSRF) in CVE-2026-66775 (CVE-2026-66775)
vulnerability in CVE-2026-66775 (CVE-2026-66775). Risk of unauthorized operations or information disclosure.
CVE-2025-32736 Cross-Site Request Forgery (CSRF) in CVE-2025-32736 (CVE-2025-32736)
vulnerability in CVE-2025-32736 (CVE-2025-32736). Risk of unauthorized operations or information disclosure.
CVE-2026-72578 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-72578)
vulnerability in csrf (CVE-2026-72578). Successful exploitation can lead to full system takeover.
CVE-2026-66642 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66642)
vulnerability in csrf (CVE-2026-66642). Risk of unauthorized operations or information disclosure.
CVE-2026-19074 Information Disclosure in wordpress (CVE-2026-19074)
vulnerability in wordpress (CVE-2026-19074). Risk of unauthorized operations or information disclosure. Exploitable via ``acadp_public_custom_fields_listings``.
CVE-2026-16965 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-16965)
vulnerability in wordpress (CVE-2026-16965). Risk of unauthorized operations or information disclosure.
CVE-2026-46409 Code Injection in CVE-2026-46409 (CVE-2026-46409)
code injection in CVE-2026-46409 (CVE-2026-46409). Successful exploitation can lead to full system takeover.
CVE-2026-16262 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-16262)
vulnerability in wordpress (CVE-2026-16262). Risk of unauthorized operations or information disclosure.
CVE-2026-66681 Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
CVE-2026-66686 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66686)
vulnerability in csrf (CVE-2026-66686). Data can be tampered with by attackers.
CVE-2026-28172 Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
CVE-2026-70556 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70556)
vulnerability in csrf (CVE-2026-70556). Risk of unauthorized operations or information disclosure.
CVE-2025-13394 Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-13394)
vulnerability in csrf (CVE-2025-13394). Risk of unauthorized operations or information disclosure.
CVE-2026-14204 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-14204)
vulnerability in wordpress (CVE-2026-14204). Data can be tampered with by attackers.
CVE-2026-14313 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-14313)
vulnerability in wordpress (CVE-2026-14313). Risk of unauthorized operations or information disclosure.
CVE-2026-66885 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66885)
vulnerability in csrf (CVE-2026-66885). Confidential information can be exposed externally.
CVE-2026-70434 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70434)
vulnerability in csrf (CVE-2026-70434). Risk of unauthorized operations or information disclosure.
CVE-2026-70432 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70432)
vulnerability in csrf (CVE-2026-70432). Successful exploitation can lead to full system takeover.
CVE-2026-7326 Cross-Site Request Forgery (CSRF) in CVE-2026-7326 (CVE-2026-7326)
vulnerability in CVE-2026-7326 (CVE-2026-7326). Successful exploitation can lead to full system takeover.
CVE-2026-71273 Cross-Site Request Forgery (CSRF) in c (CVE-2026-71273)
vulnerability in c (CVE-2026-71273). Data can be tampered with by attackers. Exploitable via ``web_admin_password_enabled``.
CVE-2026-60009 Path Traversal in eclipse (CVE-2026-60009)
path traversal in eclipse (CVE-2026-60009). Successful exploitation can lead to full system takeover. Exploitable via `POST /file-upload`.
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-70376 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70376)
vulnerability in csrf (CVE-2026-70376). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
CVE-2026-17515 Information Disclosure in wordpress (CVE-2026-17515)
vulnerability in wordpress (CVE-2026-17515). Risk of unauthorized operations or information disclosure.
CVE-2026-16613 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-16613)
vulnerability in wordpress (CVE-2026-16613). Risk of unauthorized operations or information disclosure.
CVE-2026-18819 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-18819)
vulnerability in csrf (CVE-2026-18819). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →