Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2021-46426
phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.
Phpipam
Patch available
HIGH 8.8
CVE-2022-25268
Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.
Passwork
4.6.13+
MEDIUM 5.4
CVE-2022-25608
Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into u…
Yoo Slider
after 2.0.0
MEDIUM 6.5
CVE-2021-43737
An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password.
Xiaohuanxiong Cms
No fix yet
HIGH 8.8
CVE-2021-43738
An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.
Xiaohuanxiong Cms
No fix yet
HIGH 8.8
CVE-2021-40662
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a…
Chamilo
Patch available
HIGH 8.8
CVE-2022-23349
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).
Bigant Server
Mitigation only
MEDIUM 6.5
CVE-2022-0681
The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make…
Simple Membership
4.1.0+
HIGH 8.1
CVE-2022-0229
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMet…
Google Authenticator
5.5+
HIGH 8.0
CVE-2021-24905
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX act…
Advanced Cf7 Db
1.8.7+
HIGH 8.8
CVE-2022-24235
A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code v…
Aria
No fix yet
HIGH 8.8
CVE-2022-27226EPSS 31%
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration pa…
Ru21 Firmware
after 2022-03-16
HIGH 8.8
CVE-2022-27204
A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to …
Extended Choice Parameter
after 346.vd87693c5a_86c
MEDIUM 6.5
CVE-2022-27210
A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an …
Kubernetes Continuous Deploy
after 2.3.1
HIGH 8.0
CVE-2022-27198
A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Ove…
Cloudbees Aws Credentials
1.28.2+
HIGH 8.8
CVE-2022-22346
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to exec…
Spectrum Protect Operations Center
8.1.14.000+
HIGH 8.8
CVE-2021-45886
An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weaken…
X\/p Messenger
No fix yet
HIGH 8.8
CVE-2022-25600
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (version…
Wp Maps
4.2.4+
HIGH 8.8
CVE-2022-0439
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_r…
Email Subscribers \& Newsletters
5.3.2+
MEDIUM 6.5
CVE-2022-0445
The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when reset…
Wordpress Real Cookie Banner
2.14.2+
MEDIUM 6.5
CVE-2021-25098
The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a lo…
Easy Pricing Tables
3.1.3+
HIGH 8.8
CVE-2020-18326
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a re…
Subrion Cms
Mitigation only
MEDIUM 5.0
CVE-2021-44321
Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the invento…
Mini Inventory And Sales Management System
No fix yet
MEDIUM 6.5
CVE-2022-23052
PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, …
Petereport
No fix yet
HIGH 8.8
CVE-2022-24712
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attacker…
Codeigniter
4.1.9+
CRITICAL 9.6
CVE-2021-25010
The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arb…
Post Snippets
3.1.4+
MEDIUM 5.7
CVE-2021-25011
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which co…
Wp Google Map
1.8.1+
MEDIUM 6.5
CVE-2021-25081
The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attacker…
Wp Google Map
1.8.4+
HIGH 8.8
CVE-2021-24704
In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query…
Orange Form
after 1.0
HIGH 8.8
CVE-2021-24803
The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a…
Core Tweaks Wp Setup
after 4.1