Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2021-20842
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Adminis…
Ec Cube
after 2.17.1
HIGH 8.8
CVE-2021-20845
Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authenti…
Unlimited Sitemap Generator
8.2+
HIGH 8.8
CVE-2021-20846
Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack…
Push Notifications For Wordpress
6.0.1+
HIGH 8.1
CVE-2021-24641
The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in …
Images To Webp
1.9+
MEDIUM 5.7
CVE-2021-24703
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any aut…
Download Plugin
1.6.1+
HIGH 8.8
CVE-2021-43559
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" fun…
Moodle
3.9.11 / 3.10.8+
HIGH 8.8
CVE-2021-34358
We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later
Qmailagent
3.0.2+
MEDIUM 5.4
CVE-2021-39198
OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an a…
Client Relationship Management
after 4.2.5
HIGH 8.8
CVE-2021-44036
Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.
Team Password Manager
10.135.236+
HIGH 8.8
CVE-2021-39353
The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form functi…
Easy Registration Forms
after 2.1.1
MEDIUM 6.5
CVE-2021-3976
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
Kimai 2
1.16.2+
HIGH 8.8
CVE-2021-36908
Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.
Wp Reset Pro
5.99+
HIGH 8.8
CVE-2021-41274
solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devi…
Solidus Auth Devise
2.5.4+
HIGH 8.8
CVE-2021-41275
spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by u…
Spree Auth Devise
4.4.1+
MEDIUM 6.5
CVE-2021-24852
The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make …
Mousewheel Smooth Scroll
5.7+
MEDIUM 6.5
CVE-2021-24802
The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor …
Colorful Categories
2.0.15+
HIGH 8.8
CVE-2021-24804
The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin …
Simple Jwt Login
3.2.1+
HIGH 8.8
CVE-2021-25965
In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an …
Calibre Web
after 0.6.13
HIGH 8.1
CVE-2021-25976
In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the ma…
Piranha Cms
after 9.2
MEDIUM 6.5
CVE-2021-3683
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Showdoc
after 2.9.12
MEDIUM 5.4
CVE-2021-3775
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Showdoc
after 2.9.12
MEDIUM 5.4
CVE-2021-3776
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Showdoc
after 2.9.12
HIGH 8.8
CVE-2020-21141
iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
Icms
No fix yet
MEDIUM 6.5
CVE-2020-28137
Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the rout…
Platinum 4410 Firmware
No fix yet
HIGH 8.8
CVE-2021-41426
Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.
Smart Box Firmware
No fix yet
MEDIUM 6.5
CVE-2021-40518
Airangel HSMX Gateway devices through 5.2.04 allow CSRF.
Hsmx App 25 Firmware
after 5.2.04
HIGH 7.6
CVE-2021-41372
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing H…
Power Bi Report Server
Patch available
MEDIUM 6.5
CVE-2021-24766
The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which co…
404 To 301
3.0.9+
MEDIUM 6.5
CVE-2021-24767
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which coul…
Redirect 404 Error Page To Homepage Or Custom Page With Logs
1.7.9+
HIGH 8.8
CVE-2021-24626
The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, s…
Chameleon Css
after 1.2