Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.0
CVE-2022-0154
An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all v…
GitLab
14.4.5 / 14.5.3+
HIGH 8.8
CVE-2022-0215
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable …
Login\/signup Popup
after 2.5.1
HIGH 8.8
CVE-2021-43353
The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page f…
Crisp
0.32+
HIGH 8.8
CVE-2021-4164
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
Calibre Web
0.6.15+
HIGH 8.8
CVE-2022-0180
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authenticati…
Quiz And Survey Master
7.3.7+
MEDIUM 6.5
CVE-2022-0231
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
Live Helper Chat
after 3.91
HIGH 8.8
CVE-2021-23227
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions.
Php Everywhere
after 2.0.2
HIGH 8.8
CVE-2022-0196
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
Fedora
10.8.0+
HIGH 8.8
CVE-2022-0197
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
Fedora
10.8.0+
HIGH 7.1
CVE-2022-20619
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect…
Bitbucket Branch Source
after 2.9.10
MEDIUM 5.4
CVE-2022-23115
Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Overall/Read access to retrieve…
Batch Task
after 1.19
HIGH 8.8
CVE-2021-41597
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included …
Suitecrm
7.10.35 / 7.12.2+
HIGH 8.8
CVE-2021-37198
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web …
Comos
10.3.3.3+
HIGH 8.8
CVE-2021-25051
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well …
Modal Window
5.2.2+
HIGH 8.8
CVE-2021-25052
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as w…
Button Generator
2.3.3+
HIGH 8.8
CVE-2021-25053
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as w…
Wp Coder
2.5.2+
CRITICAL 9.8
CVE-2021-25032EPSS 7%
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation …
Capabilities
2.3.1+
HIGH 8.8
CVE-2021-46147
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF.
Mediawiki
1.35.5 / 1.36.3+
HIGH 8.8
CVE-2021-34086
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver ho…
Ultimaker S3 Firmware
after 6.3
HIGH 8.8
CVE-2021-20165
Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigati…
Tew 827dru Firmware
No fix yet
MEDIUM 6.5
CVE-2020-29292
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP ad…
Wrd12en Firmware
Mitigation only
HIGH 8.8
CVE-2020-21236
A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtai…
Damicms
No fix yet
HIGH 8.8
CVE-2020-20945
A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator…
Qibosoft
No fix yet
MEDIUM 5.4
CVE-2021-24988
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which…
Wp Rss Aggregator
4.19.3+
HIGH 8.8
CVE-2021-4168
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Showdoc
2.9.15+
HIGH 8.0
CVE-2020-20593
A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.
Rockoa
No fix yet
MEDIUM 6.5
CVE-2020-20595
A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.
Opms
No fix yet
HIGH 8.8
CVE-2021-36886
Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9).
Contact Form 7 Database Addon
1.2.6.1+
MEDIUM 6.5
CVE-2021-43156
In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.
Online Book Store Project In Php
No fix yet
HIGH 7.5
CVE-2021-24981
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell upl…
Directorist
7.0.6.2+