Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2021-24674
The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logg…
Genie Wp Favicon
after 0.5.2
MEDIUM 6.5
CVE-2020-21139
EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin account…
Ec Cloud E Commerce System
No fix yet
MEDIUM 6.5
CVE-2021-34773
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Sess…
Unified Communications Manager
Mitigation only
HIGH 8.8
CVE-2020-23686
Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts.
Ayacms
No fix yet
HIGH 8.8
CVE-2021-29888
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…
Infosphere Information Server
Patch available
HIGH 8.8
CVE-2021-24809
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_be…
Better Messages
1.9.9.41+
MEDIUM 6.5
CVE-2020-36504
The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged …
Wp Pro Quiz
after 0.37
MEDIUM 6.5
CVE-2020-36505
The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthentic…
Delete All Comments Easily
after 1.3
MEDIUM 5.4
CVE-2021-24685
The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them…
Flat Preloader
1.5.4+
HIGH 8.8
CVE-2021-3901
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
Firefly Iii
after 5.6.2
MEDIUM 6.5
CVE-2021-3900
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
Firefly Iii
after 5.6.2
HIGH 8.8
CVE-2021-24487
The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and…
St Daily Tip
after 4.7
MEDIUM 6.1
CVE-2021-24543
The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor sanitise or escape its 'Quote St…
Jquery Reply To Comment
after 1.31
MEDIUM 6.5
CVE-2021-24779
The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF che…
Wp Debugging
2.11.0+
CRITICAL 9.6
CVE-2021-24884
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could …
Formidable Form Builder
4.09.05+
HIGH 8.8
CVE-2021-20120
The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an …
Arris Surfboard Sb8200 Firmware
No fix yet
MEDIUM 6.5
CVE-2021-39126
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF)…
Jira Data Center
8.5.10 / 8.13.1+
HIGH 7.1
CVE-2021-34743
A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an extern…
Webex Meetings
Mitigation only
HIGH 8.0
CVE-2021-42097
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain …
Debian Linux
2.1.35+
HIGH 8.8
CVE-2021-38480
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submi…
Ir615 Firmware
Mitigation only
HIGH 8.8
CVE-2021-3858
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
Snipe It
5.3.0+
MEDIUM 5.7
CVE-2021-24752
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authentic…
Catch Scroll Progress Bar
1.4 / 1.6+
MEDIUM 6.5
CVE-2021-24595
The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in…
Wp Cookie Choice
after 1.1.0
MEDIUM 5.4
CVE-2021-24615
The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to ma…
Wechat Reward
after 1.7
MEDIUM 6.5
CVE-2021-24642
The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or v…
Scroll Banner
after 1.0
MEDIUM 6.5
CVE-2021-24675
The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is emb…
One User Avatar
2.3.7+
MEDIUM 6.5
CVE-2021-24735
The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin chan…
Compact Wp Audio Player
1.9.7+
MEDIUM 6.5
CVE-2021-39864
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vul…
Commerce
after 2.3.7
HIGH 8.8
CVE-2021-42228
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
Kindeditor
after 4.1.12
MEDIUM 6.5
CVE-2020-19964
A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account withou…
Phpmywind
No fix yet