Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2022-20861
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…
Nexus Dashboard
2.2+
MEDIUM 6.5
CVE-2022-22359
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to …
Partner Engagement Manager
6.1.2.5 / 6.2.0.3+
MEDIUM 6.5
CVE-2021-38868
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker t…
Engineering Requirements Quality Assistant On Premises
Mitigation only
HIGH 8.8
CVE-2022-2435
The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1. This is due to missing nonc…
Anymind Widget
after 1.1
HIGH 8.8
CVE-2022-2443
The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing…
Freemind Wp Browser
after 1.2
HIGH 8.8
CVE-2022-1912
The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to …
Button Widget Smartsoft
Patch available
HIGH 8.8
CVE-2022-2001
The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing …
Dx Share Selection
1.5+
HIGH 8.8
CVE-2022-2039
The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.11. This is due to m…
Free Live Chat Support
after 1.0.11
HIGH 8.8
CVE-2022-32320
A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file s…
Ferdium
after 5.8.1
HIGH 8.8
CVE-2022-1672
The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, …
Insights From Google Pagespeed
4.0.7+
MEDIUM 6.1
CVE-2022-2146
The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking C…
Import Csv Files
after 1.0
HIGH 8.8
CVE-2022-35228
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This c…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.5
CVE-2022-2091
The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via…
Cache Images
3.2.1+
MEDIUM 6.5
CVE-2022-1576
The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attack…
Wp Maintenance Mode \& Coming Soon
2.4.5+
MEDIUM 6.5
CVE-2022-1599
The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged…
Admin Management Xtended
2.4.5+
MEDIUM 5.4
CVE-2022-1626
The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logge…
Sharebar
after 1.4.1
MEDIUM 6.5
CVE-2022-1732
The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login URL, which could allow attack…
Rename Wp Login
after 2.6.0
MEDIUM 5.4
CVE-2022-1757
The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged i…
Pagebar
2.70+
MEDIUM 6.1
CVE-2022-2353
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, …
Microweber
1.2.20+
MEDIUM 6.5
CVE-2015-1785
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web applica…
Nextgen Gallery
2.0.77.3+
MEDIUM 6.5
CVE-2021-31677
An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwords.
Pescms Team
No fix yet
MEDIUM 6.5
CVE-2021-31678
An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user's company.
Pescms Team
No fix yet
MEDIUM 6.5
CVE-2021-31679
An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other members' account numbers.
Pescms Team
No fix yet
HIGH 8.8
CVE-2021-23163
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects…
Artifactory
6.23.38 / 7.33.6+
MEDIUM 6.5
CVE-2022-1967
The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwant…
Wp Championship
9.3+
HIGH 8.0
CVE-2022-34792
A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-sp…
Recipe
after 1.2
MEDIUM 6.5
CVE-2022-34789
A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix bui…
Matrix Reloaded
after 1.1.3
MEDIUM 6.5
CVE-2022-34780
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacke…
Xebialabs Xl Release
after 22.0.0
HIGH 8.8
CVE-2017-20120
A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop…
Trueconf Server
No fix yet
MEDIUM 6.5
CVE-2022-31886
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.
Marval Msm
No fix yet