Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2021-25095
The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_ru…
Country Blocker
2.26.5+
MEDIUM 6.5
CVE-2021-24947
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in…
Responsive Vector Maps
6.4.2+
MEDIUM 6.5
CVE-2021-24993
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any a…
Ultimate Product Catalog
5.0.26+
MEDIUM 6.5
CVE-2021-24843
The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged…
Supportcandy
2.2.7+
HIGH 8.8
CVE-2021-24879
The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some…
Supportcandy
2.2.7+
MEDIUM 6.5
CVE-2021-32732
### Impact It's possible to know if a user has or not an account in a wiki related to an email address, and which username(s) is actually tied to tha…
Xwiki
12.10.5+
HIGH 8.8
CVE-2020-7534
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized a…
Modicon M340 Bmxp342020 Firmware
Patch available
HIGH 8.8
CVE-2021-46398EPSS 7%
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and ge…
Filebrowser
2.18.0+
HIGH 8.8
CVE-2021-45268
A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on t…
Backdrop
No fix yet
HIGH 8.8
CVE-2021-39044
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…
Financial Transaction Manager
Mitigation only
HIGH 8.8
CVE-2022-23601
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protecti…
Symfony
5.3.15 / 5.4.4+
MEDIUM 6.5
CVE-2021-25072
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker …
Social Networks Auto Poster
4.3.25+
MEDIUM 6.5
CVE-2021-25092
The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin…
Link Library
7.2.8+
MEDIUM 6.5
CVE-2021-25097
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authent…
Labtools
after 1.0
MEDIUM 6.5
CVE-2021-24761
The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention,…
Error Log Viewer
1.1.2+
HIGH 8.8
CVE-2021-24763
The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing …
Perfect Survey
1.5.2+
MEDIUM 6.5
CVE-2022-23887
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin…
Yzmcms
No fix yet
HIGH 8.8
CVE-2022-23888
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.
Yzmcms
No fix yet
HIGH 8.8
CVE-2021-22724
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their b…
Evc1s22p4 Firmware
3.4.0.2+
HIGH 8.8
CVE-2021-22725
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their b…
Evc1s22p4 Firmware
3.4.0.2+
HIGH 8.8
CVE-2021-44122
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/…
Spip
Patch available
HIGH 8.8
CVE-2022-0335
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" f…
Moodle
3.9.12 / 3.10.9+
HIGH 8.0
CVE-2022-0269
Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.
Yetiforce Customer Relationship Management
6.3.0+
MEDIUM 6.5
CVE-2021-24989
The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belo…
Accept Donations With Paypal
1.3.4+
MEDIUM 6.5
CVE-2021-25013
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure…
Qubely
1.7.8+
HIGH 8.8
CVE-2021-25073
The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a lo…
Wp125
1.5.5+
HIGH 8.8
CVE-2021-24696
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) ma…
Simple Download Monitor
3.9.9+
HIGH 8.0
CVE-2021-24936
The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which …
Wp Extra File Types
0.5.1+
MEDIUM 5.7
CVE-2021-24968
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_…
Ultimate Faq
2.1.2+
MEDIUM 6.5
CVE-2021-46027
mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrato…
Mysiteforme
No fix yet