Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-29839
DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.
Dedecms
Mitigation only
MEDIUM 6.5
CVE-2026-33252
The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site…
Mcp Go Sdk
1.4.1+
HIGH 8.8
CVE-2026-33649
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts …
Avideo
after 26.0
HIGH 8.8
CVE-2026-33507
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users t…
Avideo
after 26.0
MEDIUM 6.5
CVE-2026-31849
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setS…
Nebula300plus Firmware
after 12.01.01.37
MEDIUM 6.1
CVE-2026-2723
The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing …
Mitigation only
HIGH 8.1
CVE-2025-14037
The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1.2…
Mitigation only
HIGH 8.8
CVE-2026-32989
Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafte…
Intranet Portal
No fix yet
MEDIUM 5.4
CVE-2026-33372
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due t…
Zimbra Collaboration Suite
10.1.16+
HIGH 7.1
CVE-2024-32537
Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This issue affects Flash Video Pl…
Mitigation only
MEDIUM 5.7
CVE-2026-32755
Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/profile/profile_function.php s…
Admidio
5.0.7+
MEDIUM 5.7
CVE-2026-32816
Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivate modes in modules/groups-rol…
Admidio
5.0.7+
HIGH 8.8
CVE-2025-55040
The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack…
Mura Cms
Mitigation only
HIGH 8.0
CVE-2025-55041
MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allow…
Mura Cms
Mitigation only
MEDIUM 6.5
CVE-2025-55043
MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenti…
Mura Cms
Mitigation only
HIGH 8.8
CVE-2025-55044
The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations …
Mura Cms
Mitigation only
HIGH 7.1
CVE-2025-55045
The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable…
Mura Cms
Mitigation only
HIGH 8.1
CVE-2025-55046
MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system thr…
Mura Cms
Mitigation only
HIGH 7.1
CVE-2026-22323
A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into send…
Mitigation only
MEDIUM 6.5
CVE-2026-32839
Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauth…
Gs 5008pl Firmware
after 1.00.54
HIGH 8.0
CVE-2016-20034
Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to adminis…
Streaming Engine
No fix yet
HIGH 8.8
CVE-2015-20117
Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthoriz…
Realtyscript
No fix yet
MEDIUM 6.5
CVE-2026-32443
Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohlbach Product Feed PRO for WooCommerce woo-product-feed-pro allows Cross Site Request Forg…
Mitigation only
MEDIUM 5.4
CVE-2026-32420
Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Site Request Forgery.This issue affects GamiPress: f…
Mitigation only
MEDIUM 5.4
CVE-2026-32328
Cross-Site Request Forgery (CSRF) vulnerability in shufflehound Lemmony lemmony allows Cross Site Request Forgery.This issue affects Lemmony: from n/…
Mitigation only
MEDIUM 5.4
CVE-2026-22215
wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows attackers to trigger unauthor…
Wpdiscuz
7.6.47+
MEDIUM 6.5
CVE-2026-22202
wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email addr…
Wpdiscuz
7.6.47+
HIGH 7.3
CVE-2026-31954
Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::check…
Emlog
after 2.6.6
HIGH 8.1
CVE-2026-30868
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but…
Opnsense
26.1.4+
HIGH 8.1
CVE-2026-2626
The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated us…
Mitigation only