CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,489 vulnerabilities with CWE-352
CVE-2026-60842
MEDIUM
Oracle Knowledge Mgmt 12.2.5-12.2.15: Unauth CSRF & Data Disclosure via HTTP Search
CVSS 6.1
CVE-2026-60685
MEDIUM
Oracle iSupport 12.2.3-12.2.15 - Unauthenticated Cross-Site Request Forgery via HTTP with Impact to Additional Products
CVSS 6.1
CVE-2026-60664
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60658
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 7.5
CVE-2026-60650
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60648
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60646
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60643
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Content Server
CVSS 8.0
CVE-2026-60642
HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.6
CVE-2026-60640
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.3
CVE-2026-60639
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60638
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60637
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60636
HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60635
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60634
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60633
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60631
CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Arbitrary Data Creation, Deletion, and Access via HTTP
CVSS 9.3
CVE-2026-47000
LOW
Oracle Enterprise Manager Base Platform 24.1 - Authenticated Data Modification via Security Framework
CVSS 3.5
CVE-2026-64821
MEDIUM
djangoSIGE 1.10 CSRF via GET-based Order Cancellation Views
CVSS 4.3
CVE-2026-58482
MEDIUM
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
CVSS 5.9
CVE-2026-50743
MEDIUM
Revive Adserver < 6.0.7 - Cross-Site Request Forgery (CSRF)
CVSS 5.4
CVE-2026-32823
MEDIUM
dataCycle State-Changing GET Endpoints Enable CSRF
CVSS 4.3
CVE-2026-13156
MEDIUM
MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
CVSS 5.4
CVE-2026-16216
MEDIUM
geex-arts django-jet OAuth cross-site request forgery
CVSS 4.3
Details
Vulnerabilities
9,489
Exploit Likelihood
Medium