Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2022-1407
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does n…
Hotel Booking Engine \& Pms
1.5.8+
MEDIUM 6.1
CVE-2022-1418
The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape …
Social Stickers
after 2.2.9
MEDIUM 6.5
CVE-2021-27758
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and s…
Bigfix Inventory
10.0.7.0+
MEDIUM 6.5
CVE-2021-27759
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intent…
Bigfix Inventory
10.0.7.0+
HIGH 8.8
CVE-2022-25778
Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user sess…
Gatemanager 4250 Firmware
9.7.622134021+
HIGH 8.8
CVE-2022-0916
An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF at…
Options
9.60.87+
MEDIUM 6.5
CVE-2022-0191
The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to ma…
Ad Invalid Click Protector
1.2.7+
HIGH 8.8
CVE-2022-0952EPSS 11%
The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does …
Sitemap
1.0.36+
HIGH 8.0
CVE-2022-23904
Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to …
Auctionworx
after 3.1
MEDIUM 5.4
CVE-2022-29414
Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows atta…
Subscribe To Comments Reloaded
after 211130
HIGH 8.8
CVE-2022-29451
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows at…
Rara One Click Demo Import
1.3.0+
HIGH 8.8
CVE-2021-43937
Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intenti…
Scada Server
No fix yet
HIGH 8.8
CVE-2022-29555
The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.
Mender
3.2.2+
MEDIUM 5.4
CVE-2022-29412
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers to delete cache, delete …
Hermit
after 3.1.6
MEDIUM 6.1
CVE-2022-29413
Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress via &title …
Hermit
after 3.1.6
MEDIUM 6.1
CVE-2022-27860
Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress.
Footer Text
after 2.0.3
HIGH 8.8
CVE-2022-28892
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too eas…
Mahara
20.10.5 / 21.04.4+
HIGH 7.5
CVE-2022-24879
Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) t…
Shopware
5.7.9+
MEDIUM 6.5
CVE-2022-27374
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot.
Ax12 Firmware
No fix yet
MEDIUM 6.5
CVE-2022-27375
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet.
Ax12 Firmware
No fix yet
MEDIUM 5.4
CVE-2022-0398
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links…
Thirstyaffiliates Affiliate Link Manager
3.10.5+
HIGH 8.8
CVE-2022-27340
MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges an…
Mcms
No fix yet
HIGH 8.8
CVE-2021-38886
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…
Cognos Analytics
Patch available
HIGH 8.8
CVE-2021-32929
All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user.
Gps Tracker
No fix yet
MEDIUM 6.8
CVE-2022-20787
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Mana…
Unified Communications Manager
12.5 / 14su1+
HIGH 8.8
CVE-2022-27629
Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership' versions prior to 1.9.…
Micropayments
1.9.6+
HIGH 8.8
CVE-2021-4096
The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for…
Fancy Product Designer
after 4.7.5
HIGH 8.8
CVE-2022-28108EPSS 12%
Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data,…
Selenium Grid
4.0.0+
MEDIUM 5.4
CVE-2022-1112
The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape th…
Autolinks
after 1.0.1
CRITICAL 9.8
CVE-2022-1020EPSS 26%
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update…
Woo Product Table
3.1.2+